diff --git a/molecule/os_hardening/verify_tasks/ssh_auth_locked.yml b/molecule/os_hardening/verify_tasks/ssh_auth_locked.yml index ba79fc35..d34969c6 100644 --- a/molecule/os_hardening/verify_tasks/ssh_auth_locked.yml +++ b/molecule/os_hardening/verify_tasks/ssh_auth_locked.yml @@ -12,6 +12,13 @@ ansible.builtin.service: name: sshd state: started + ignore_errors: true + +- name: Start ssh service + ansible.builtin.service: + name: ssh + state: started + ignore_errors: true - name: Set password for test ansible.builtin.set_fact: @@ -37,11 +44,11 @@ - name: Check successful login with password ansible.builtin.shell: - cmd: sshpass -p {{ test_pw }} ssh locked_user@localhost echo "success" + cmd: sshpass -p {{ test_pw }} ssh -o StrictHostKeyChecking=no locked_user@localhost echo "success" - name: Check successful login with ssh key ansible.builtin.shell: - cmd: ssh -i /root/locked_user_id locked_user@localhost echo "success" + cmd: ssh -i /root/locked_user_id -o StrictHostKeyChecking=no locked_user@localhost echo "success" - name: Set password change date for locked_user ansible.builtin.shell: @@ -49,7 +56,7 @@ - name: Check unsuccessful login with password ansible.builtin.shell: - cmd: sshpass -p {{ test_pw }} ssh locked_user@localhost echo "success" + cmd: sshpass -p {{ test_pw }} ssh -o StrictHostKeyChecking=no locked_user@localhost echo "success" register: output ignore_errors: true @@ -62,4 +69,4 @@ - name: Check successful login with ssh key ansible.builtin.shell: - cmd: ssh -i /root/locked_user_id locked_user@localhost echo "success" + cmd: ssh -i /root/locked_user_id -o StrictHostKeyChecking=no locked_user@localhost echo "success"