This will fix the follwing issues when using the centos/7 box for role testing: * TASK [../../../openstack-ansible-security : V-38476 ... fatal: [centos7]: FAILED! => {"changed": false, "failed": true, "msg": "Missing CentOS 7 GPG keys"} The required gpg-pubkey packages are created after the import of the provided signing keys in /etc/pki/rpm-gpg. * TASK [../../../openstack-ansible-security : V-38574 ... fatal: [centos7]: FAILED! => {"changed": false, "failed": true, "msg": "Must use SHA512 for password hashing (via PAM)"} sha512 instead of md5 has to be used in /etc/pam.d/password-auth * TASK [../../../openstack-ansible-security : Check password hashing algorithm used in login.defs (for V-38576)] *** fatal: [centos7]: FAILED! => {"changed": true, "cmd": "grep '^ENCRYPT_METHOD.*SHA512' /etc/login.defs", ... sha512 instead of md5 has to be used in /etc/login.defs Change-Id: Ia40119dbf933b8102001cfe914312b17632bcf65 Co-authored-by: David Rabel <rabel@b1-systems.de>changes/29/439529/1
parent
83e3c206e8
commit
dd52e48925
Loading…
Reference in new issue