INNER CODE UNIT · Shell
ALL
cipi-sh/cipi · setup.sh:315
cipi ALL=(root) NOPASSWD: /usr/local/bin/cipi *
SUDOEOF
chmod 440 /etc/sudoers.d/cipi-sudo
# 5. Harden sshd_config
local SSHD="/etc/ssh/sshd_config"
cp "$SSHD" "${SSHD}.bak.$(date +%s)"
# Apply settings (replace if exists, append if not)
local -A ssh_settings=(
[PermitRootLogin]="no"
[PasswordAuthentication]="no"
[PubkeyAuthentication]="yes"
[PermitEmptyPasswords]="no"
[MaxAuthTries]="3"
[LoginGraceTime]="20"
[X11Forwarding]="no"
[AllowGroups]="cipi-ssh cipi-apps"