From 96977b4b2f303c107a8ad26de9624f41b112850c Mon Sep 17 00:00:00 2001 From: kris Date: Wed, 29 Apr 2026 16:24:18 +0100 Subject: [PATCH] Add user_password.yml --- user_password.yml | 51 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) create mode 100644 user_password.yml diff --git a/user_password.yml b/user_password.yml new file mode 100644 index 0000000..7d0f108 --- /dev/null +++ b/user_password.yml @@ -0,0 +1,51 @@ +--- +# set_user_password.yml +# +# Sets a user's password and forces them to change it on next login. +# +# Usage: +# ansible-playbook set_user_password.yml \ +# -i inventory.ini \ +# -e "target_user=alice new_password=TempPass123!" +# +# Variables (pass with -e or define in vars/group_vars): +# target_user – the Linux username to configure (required) +# new_password – the plaintext temporary password (required) + +- name: Set user password and force change on next login + hosts: all + become: true + + vars: + target_user: "{{ target_user | mandatory }}" + new_password: "{{ new_password | mandatory }}" + + tasks: + + - name: Ensure the user account exists + ansible.builtin.user: + name: "{{ target_user }}" + state: present + shell: /bin/bash + + - name: Set the user's password (hashed) + ansible.builtin.user: + name: "{{ target_user }}" + # password filter hashes the plaintext with SHA-512 + password: "{{ new_password | password_hash('sha512') }}" + update_password: always + + - name: Force password change on next login (chage -d 0) + ansible.builtin.command: + cmd: "chage -d 0 {{ target_user }}" + changed_when: true # chage always returns 0; mark as changed for clarity + + - name: Verify password expiry settings + ansible.builtin.command: + cmd: "chage -l {{ target_user }}" + register: chage_output + changed_when: false + + - name: Show password expiry info + ansible.builtin.debug: + var: chage_output.stdout_lines \ No newline at end of file