diff --git a/user_password.yml b/user_password.yml new file mode 100644 index 0000000..7d0f108 --- /dev/null +++ b/user_password.yml @@ -0,0 +1,51 @@ +--- +# set_user_password.yml +# +# Sets a user's password and forces them to change it on next login. +# +# Usage: +# ansible-playbook set_user_password.yml \ +# -i inventory.ini \ +# -e "target_user=alice new_password=TempPass123!" +# +# Variables (pass with -e or define in vars/group_vars): +# target_user – the Linux username to configure (required) +# new_password – the plaintext temporary password (required) + +- name: Set user password and force change on next login + hosts: all + become: true + + vars: + target_user: "{{ target_user | mandatory }}" + new_password: "{{ new_password | mandatory }}" + + tasks: + + - name: Ensure the user account exists + ansible.builtin.user: + name: "{{ target_user }}" + state: present + shell: /bin/bash + + - name: Set the user's password (hashed) + ansible.builtin.user: + name: "{{ target_user }}" + # password filter hashes the plaintext with SHA-512 + password: "{{ new_password | password_hash('sha512') }}" + update_password: always + + - name: Force password change on next login (chage -d 0) + ansible.builtin.command: + cmd: "chage -d 0 {{ target_user }}" + changed_when: true # chage always returns 0; mark as changed for clarity + + - name: Verify password expiry settings + ansible.builtin.command: + cmd: "chage -l {{ target_user }}" + register: chage_output + changed_when: false + + - name: Show password expiry info + ansible.builtin.debug: + var: chage_output.stdout_lines \ No newline at end of file