--- - name: Update PAM configuration # noqa no-changed-when # [no-changed-when] Commands should not change things if nothing needs doing # This task is invoked only if user is very specific about requiring to # run the handlers manually as a way to bring the system to consistency # after interrupted runs. ansible.builtin.command: "/usr/sbin/pam-auth-update --package" - name: Restart SSH ansible.builtin.service: name: ssh state: restarted - name: Update CA certificate cache # noqa no-changed-when # [no-changed-when] Commands should not change things if nothing needs doing # This task is invoked only if user is very specific about requiring to # run the handlers manually as a way to bring the system to consistency # after interrupted runs. ansible.builtin.command: "/usr/sbin/update-ca-certificates --fresh" - name: Restart ferm ansible.builtin.service: name: ferm state: restarted - name: Reload systemd ansible.builtin.systemd: daemon_reload: true - name: Restart NTP server ansible.builtin.service: name: ntpsec state: restarted when: ntp_pools | length > 0