|
12 | 12 |
|
13 | 13 | - name: remove pam ccreds on Redhat systems |
14 | 14 | yum: name='{{os_packages_pam_ccreds}}' state=absent |
15 | | - when: ansible_os_family == 'RedHat' or ansible_os_family == 'Oracle Linux' |
| 15 | + when: ansible_os_family == 'RedHat' |
16 | 16 |
|
17 | 17 | - name: remove pam_cracklib, because it does not play nice with passwdqc |
18 | 18 | apt: name='{{os_packages_pam_cracklib}}' state=absent |
|
44 | 44 |
|
45 | 45 | - name: remove pam_cracklib, because it does not play nice with passwdqc |
46 | 46 | yum: name='{{os_packages_pam_cracklib}}' state='absent' |
47 | | - when: ((ansible_distribution == 'RedHat' or ansible_distribution == 'Oracle Linux' and ansible_distribution_version <= '7')) and os_auth_pam_passwdqc_enable |
| 47 | + when: (ansible_os_family == 'RedHat' and ansible_distribution_version < '7') and os_auth_pam_passwdqc_enable |
48 | 48 |
|
49 | 49 | - name: install the package for strong password checking |
50 | 50 | yum: name='{{os_packages_pam_passwdqc}}' state='installed' |
51 | | - when: ((ansible_distribution == 'RedHat' or ansible_distribution == 'Oracle Linux' and ansible_distribution_version <= '7')) and os_auth_pam_passwdqc_enable |
52 | | - |
53 | | -- name: install pam_pwquality on rhel7, replacement for pam_passwdqc and pam_cracklib |
54 | | - yum: name='{{os_packages_pam_pwquality}}' state='installed' |
55 | | - when: ((ansible_distribution == 'RedHat' or ansible_distribution == 'Oracle Linux' and ansible_distribution_version >= '7')) and os_auth_pam_passwdqc_enable |
| 51 | + when: (ansible_os_family == 'RedHat' and ansible_distribution_version < '7') and os_auth_pam_passwdqc_enable |
56 | 52 |
|
57 | 53 | - name: remove passwdqc |
58 | 54 | yum: name='{{os_packages_pam_passwdqc}}' state='absent' |
59 | | - when: (ansible_distribution == 'RedHat' or ansible_distribution == 'Oracle Linux') and not os_auth_pam_passwdqc_enable |
| 55 | + when: ansible_os_family == 'RedHat' and not os_auth_pam_passwdqc_enable |
60 | 56 |
|
61 | 57 | - name: configure passwdqc and tally via central system-auth confic |
62 | 58 | template: src='rhel_system_auth.j2' dest='/etc/pam.d/system-auth-ac' mode=0640 owner=root group=root |
|
0 commit comments