Replies: 1 comment
-
|
Hello from 2025 @Tronde! I have only done this with Ansible and Puppet in a single company with el6, 7, 9 but ended up doing exactly what you have described: just include different tasks/modules depending on the target. It worked ok but happy to hear if there are better ideas out there. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Dear System Roles Community,
I would like to share an idea with you that originated in a discussion with another systems administrator.
My contact has asked me how to configure and manage authentication settings across different RHEL major releases at scale. They face the challenge that the different releases ship different tools. For example, RHEL 7 uses
authconfigwhile RHEL 8 and 9 useauthselectandsssctl. Of course you should not useauthselectwhen your host ist part of Red Hat Enterprise Linux Identity Management (IdM) as joining your host to an IdM domain with theipa-client-installcommand automatically configures SSSD authentication on your host. And editing the PAM files directly is AFAIK also not recommended. Therefore enhancing pam_pwd or creating a similar role does not seem reasonable.I understand the desire to have one consistent way to deploy or template the target configuration to all hosts across the infrastructure. Only I lack an idea on how to accomplish this and if it's even possible with reasonable effort. And that's why I brought this topic to the table.
Looking forward to hearing your thoughts on this.
Best regards,
Joerg
Beta Was this translation helpful? Give feedback.
All reactions