]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/named/templates/named.conf.puppet-shared-keys.erb
add some ugliness
[dsa-puppet.git] / modules / named / templates / named.conf.puppet-shared-keys.erb
index 07172b1f64d39d680db3131d601abf069beecf4c..71cc4132199fe5164b544d2c0bc8607f9e57b766 100644 (file)
@@ -9,7 +9,8 @@ pairs = [
        [ 'denis.debian.org', 'ravel.debian.org' ],
        [ 'denis.debian.org', 'senfl.debian.org' ],
        [ 'denis.debian.org', 'diamond.debian.org' ],
-       [ 'denis.debian.org', 'orff.debian.org' ]
+       [ 'denis.debian.org', 'orff.debian.org' ],
+       [ 'denis.debian.org', 'xfr0.easydns.com' ]
        ]
 
 lines = []
@@ -21,13 +22,17 @@ pairs.each do |pair|
        pair.delete(fqdn)
        other = pair[0]
 
-       key = hkdf('/etc/puppet/secret', "puppet-key-#{keyname}")
+       key = scope.function_hkdf(['/etc/puppet/secret', "puppet-key-#{keyname}"])
 
-       lines << "key #{keyname} { algorithm hmac-md5; secret \"#{key}\"; };\n"
+       lines << "key #{keyname} { algorithm hmac-sha256; secret \"#{key}\"; };"
 
-       remote_ip = scope.lookupvar('site::allnodeinfo')[other]['ipHostNumber']
+       if other == 'xfr0.easydns.com'
+               remote_ip = '64.68.200.91'
+       else
+               remote_ip = scope.lookupvar('site::allnodeinfo')[other]['ipHostNumber']
+       end
        remote_ip.each do |r|
-               lines << "server #{r} { keys { #{keyname}; }; };\n"
+               lines << "server #{r} { keys { #{keyname}; }; };"
        end
        lines << ""
 end