ansible-collection-hardening icon indicating copy to clipboard operation
ansible-collection-hardening copied to clipboard

do not manage trusted user ca keys if none exist

Open hollow opened this issue 2 years ago • 0 comments

We are using Okta Advanced Server Access (formerly ScaleFT) and we need to configure sshd with the trusted user ca from Okta.

When setting ssh_trusted_user_ca_keys_file to the ca file managed by sftd this role overwrites this file every time and sshd is being restarted.

This change disables management of the ca file if no ca keys are set in ssh_trusted_user_ca_keys.

hollow avatar Sep 18 '22 08:09 hollow