]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/ssl/manifests/init.pp
ferm: change ferm.conf to a template
[dsa-puppet.git] / modules / ssl / manifests / init.pp
index 0ae64aa4ed8f9638377fb5f390fac4a5f3c090cd..5aedfbc9f382d9c80d9d9238adf71bd1f20983a9 100644 (file)
@@ -11,17 +11,21 @@ class ssl {
                ensure   => installed,
        }
 
+       file { '/etc/ssl/README':
+               mode   => '0444',
+               source => 'puppet:///modules/ssl/README',
+       }
        file { '/etc/ca-certificates.conf':
-               content => "# This file is under puppet control\n# Only debian.org service certs are trusted, see /etc/ssl/certs/README\n",
+               source => 'puppet:///modules/ssl/ca-certificates.conf',
                notify  => Exec['refresh_normal_hashes'],
        }
        file { '/etc/ca-certificates-debian.conf':
                mode    => '0444',
-               content => "# This file is under puppet control\n# Only the CAs for debian.org are trusted, see /etc/ssl/ca-debian/README\nmozilla/AddTrust_External_Root.crt\nmozilla/UTN_USERFirst_Hardware_Root_CA.crt\nspi-inc.org/spi-cacert-2008.crt\n",
+               source => 'puppet:///modules/ssl/ca-certificates-debian.conf',
                notify  => Exec['refresh_ca_debian_hashes'],
        }
        file { '/etc/ca-certificates-global.conf':
-               content => "# This file is under puppet control\n# All CAs are trusted, see /etc/ssl/ca-global/README\n",
+               source => 'puppet:///modules/ssl/ca-certificates-global.conf',
                notify  => Exec['refresh_ca_global_hashes'],
        }
 
@@ -56,24 +60,21 @@ class ssl {
                notify   => Exec['refresh_normal_hashes'],
        }
        file { '/etc/ssl/certs/README':
-               mode   => '0444',
-               source => 'puppet:///modules/ssl/README.certs',
+               ensure => absent,
        }
        file { '/etc/ssl/ca-debian':
                ensure => directory,
                mode   => '0755',
        }
        file { '/etc/ssl/ca-debian/README':
-               mode   => '0444',
-               source => 'puppet:///modules/ssl/README.ca-debian',
+               ensure => absent,
        }
        file { '/etc/ssl/ca-global':
                ensure => directory,
                mode   => '0755',
        }
        file { '/etc/ssl/ca-global/README':
-               mode   => '0444',
-               source => 'puppet:///modules/ssl/README.ca-global',
+               ensure => absent,
        }
        file { '/etc/ssl/debian':
                ensure   => directory,