From 3346bd0e0883aec78c7b6431506b7851d7d5887d Mon Sep 17 00:00:00 2001 From: Denis Knauf Date: Sun, 24 Mar 2024 23:23:35 +0100 Subject: [PATCH] fix newline in sshd-default.conf j2-template. sshd_host_keys must be an array! --- defaults/main.yml | 3 ++- templates/sshd-default.conf.j2 | 1 + 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/defaults/main.yml b/defaults/main.yml index f46a87e..a6efbb8 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -6,5 +6,6 @@ sshd_permit_root_login: 'prohibit-password' sshd_ciphers: 'chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr' sshd_macs: 'hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com' sshd_kex_algorithms: 'sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256' -sshd_host_keys: /etc/ssh/ssh_host_ed25519_key +sshd_host_keys: +- '/etc/ssh/ssh_host_ed25519_key' sshd_pubkey_authentication: 'yes' diff --git a/templates/sshd-default.conf.j2 b/templates/sshd-default.conf.j2 index 0ec1c11..5b5159e 100644 --- a/templates/sshd-default.conf.j2 +++ b/templates/sshd-default.conf.j2 @@ -1,3 +1,4 @@ +#jinja2: trim_blocks:False {%if sshd_port is defined %}Port {{sshd_port}}{%endif%} PermitRootLogin {{sshd_permit_root_login}} StrictModes yes