1 class entropykey::provider {
3 "ekeyd": ensure => installed;
7 "/etc/entropykey/ekeyd.conf":
8 source => "puppet:///modules/entropykey/ekeyd.conf",
9 notify => Exec['restart_ekeyd'],
10 require => [ Package['ekeyd'] ],
12 # our CRL expires after a while (2 or 4 weeks?), so we have
13 # to restart stunnel so it loads the new CRL.
14 "/etc/cron.weekly/stunnel-ekey.conf":
15 content => "# This file is under puppet control\nenv -i /etc/init.d/stunnel4 restart puppet-ekeyd\n",
23 command => "true && cd / && env -i /etc/init.d/ekeyd restart",
24 require => [ File['/etc/entropykey/ekeyd.conf'] ],
30 stunnel4::stunnel_server {
33 connect => "127.0.0.1:8888",
38 class entropykey::local_consumer {
40 "ekeyd-egd-linux": ensure => installed;
44 "/etc/default/ekeyd-egd-linux":
45 source => "puppet:///modules/entropykey/ekeyd-egd-linux",
46 notify => Exec['restart_ekeyd-egd-linux'],
47 require => [ Package['ekeyd-egd-linux'] ],
52 "restart_ekeyd-egd-linux":
53 command => "true && cd / && env -i /etc/init.d/ekeyd-egd-linux restart",
54 require => [ File['/etc/default/ekeyd-egd-linux'] ],
60 class entropykey::remote_consumer inherits entropykey::local_consumer {
62 stunnel4::stunnel_client {
64 accept => "127.0.0.1:8888",
65 connecthost => "${entropy_provider}",
72 case getfromhash($nodeinfo, 'entropy_key') {
73 true: { include entropykey::provider }
76 $entropy_provider = entropy_provider($fqdn, $nodeinfo)
77 case $entropy_provider {
79 local: { include entropykey::local_consumer }
80 default: { include entropykey::remote_consumer }
87 # vim:set shiftwidth=4: