]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/ssh/manifests/init.pp
move all files to explicit new-style module/ paths
[dsa-puppet.git] / modules / ssh / manifests / init.pp
index e560961c024ba8ee37a477cdb6af79ad911e57d5..271c8bdff6155c00a448f453ca4dbae244e52129 100644 (file)
@@ -5,7 +5,7 @@ class ssh {
         }
 
        file { "/etc/ssh/ssh_config":
-               source  => [ "puppet:///ssh/ssh_config" ],
+               source  => [ "puppet:///modules/ssh/ssh_config" ],
                require => Package["openssh-client"]
                 ;
               "/etc/ssh/sshd_config":
@@ -13,14 +13,34 @@ class ssh {
                require => Package["openssh-server"],
                 notify  => Exec["ssh restart"]
                 ;
-#                "/etc/ssh/userkeys/root":
-#              content => template("ssh/authorized_keys.erb" ],
-#              require => Package["openssh-server"]
-#                ;
+              "/etc/ssh/userkeys":
+               ensure  => directory,
+               owner   => root,
+               group   => root,
+               mode    => 755,
+                ;
+              "/etc/ssh/userkeys/root":
+                content => template("ssh/authorized_keys.erb"),
+                mode    => 444,
+                require => Package["openssh-server"]
+                ;
        }
 
         exec { "ssh restart":
             path        => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
             refreshonly => true,
         }
+
+        @ferm::rule { "dsa-ssh":
+                description     => "Allow SSH from DSA",
+                rule            => "&SERVICE_RANGE(tcp, ssh, \$SSH_SOURCES)"
+        }
+        @ferm::rule { "dsa-ssh-v6":
+                description     => "Allow SSH from DSA",
+                domain          => "ip6",
+                rule            => "&SERVICE_RANGE(tcp, ssh, \$SSH_V6_SOURCES)"
+        }
 }
+# vim:set et:
+# vim:set sts=4 ts=4:
+# vim:set shiftwidth=4: