ansible-roles/proftpd/tasks/accounts_password.yml

46 lines
1.2 KiB
YAML

---
- name: Check if FTP account exist
ansible.builtin.command:
cmd: grep "^{{ item.name }}:" /etc/proftpd/vpasswd
failed_when: False
check_mode: no
changed_when: check_ftp_account.rc != 0
register: check_ftp_account
- block:
- name: Get current FTP password
ansible.builtin.shell:
cmd: grep "^{{ item.name }}:" /etc/proftpd/vpasswd | cut -d':' -f2
register: protftpd_cur_password
check_mode: no
changed_when: False
- name: Set password for this account
ansible.builtin.set_fact:
protftpd_password: "{{ protftpd_cur_password.stdout }}"
when: check_ftp_account.rc == 0
- block:
- name: Generate FTP password
ansible.builtin.command:
cmd: "apg -n 1 -m 16 -M lcN"
register: proftpd_apg_password
check_mode: no
- name: Print generated password
ansible.builtin.debug:
msg: "{{ proftpd_apg_password.stdout }}"
- name: Hash generated password
ansible.builtin.set_fact:
protftpd_password: "{{ proftpd_apg_password.stdout | password_hash('sha512') }}"
when: check_ftp_account.rc != 0
- name: Update proftpd_accounts with password
ansible.builtin.set_fact:
proftpd_accounts_final: "{{ proftpd_accounts_final + [ item | combine({ 'password': protftpd_password }) ] }}"