[ 'denis.debian.org', 'ravel.debian.org' ],
[ 'denis.debian.org', 'senfl.debian.org' ],
[ 'denis.debian.org', 'diamond.debian.org' ],
- [ 'denis.debian.org', 'orff.debian.org' ]
+ [ 'denis.debian.org', 'orff.debian.org' ],
+ [ 'denis.debian.org', 'xfr0.easydns.com' ]
]
lines = []
pairs.each do |pair|
next unless pair.include?(fqdn)
pair.sort!
- keyname = "tsig-#{pair.join('-')}"
pair.delete(fqdn)
other = pair[0]
- key = hkdf('/etc/puppet/secret', "puppet-key-#{keyname}")
-
- lines << "key #{keyname} { algorithm hmac-md5; secret \"#{key}\"; };\n"
+ if other == 'xfr0.easydns.com'
+ remote_ip = ['64.68.200.91']
+ algorithm = "hmac-md5";
+ keyname = "82.195.75.91-key"
+ key = "VoIkCnR5DaI3QP3xtmdCYg=="
+ else
+ remote_ip = scope.lookupvar('site::allnodeinfo')[other]['ipHostNumber']
+ algorithm = "hmac-sha256";
+ keyname = "tsig-#{pair.join('-')}"
+ key = scope.function_hkdf(['/etc/puppet/secret', "puppet-key-#{keyname}"])
+ end
- remote_ip = scope.lookupvar('site::allnodeinfo')[other]['ipHostNumber']
+ lines << "key #{keyname} { algorithm #{algorithm}; secret \"#{key}\"; };"
remote_ip.each do |r|
- lines << "server #{r} { keys { #{keyname}; }; };\n"
+ lines << "server #{r} { keys { #{keyname}; }; };"
end
lines << ""
end