Explorar o código

fix: fix insecure file permission and ownership

Christoph Schug %!s(int64=2) %!d(string=hai) anos
pai
achega
b46f18d437

+ 4 - 1
ansible/configuration/fail2ban/config-f2b-protect-sshd.yaml

@@ -10,10 +10,13 @@
           - fail2ban
         update_cache: true
 
-    - name: Copy fail2ban configfiles
+    - name: Copy fail2ban config file
       ansible.builtin.copy:
         src: configfiles/debian-sshd-default.conf
         dest: /etc/fail2ban/jail.d/debian-sshd-default.conf
+        mode: '0644'
+        owner: root
+        group: root
 
     - name: Restart fail2ban
       ansible.builtin.systemd_service: