]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/named/templates/named.conf.puppet-shared-keys.erb
Remove secondary DNS from senfl
[dsa-puppet.git] / modules / named / templates / named.conf.puppet-shared-keys.erb
index e9f7022bbcfead0a00e76482aa57f031f38e4dbd..8027c895210ea1007a95ef8cdc5ee507552aa9d4 100644 (file)
@@ -6,10 +6,11 @@
 <%=
 
 pairs = [
-       [ 'denis.debian.org', 'ravel.debian.org' ],
-       [ 'denis.debian.org', 'senfl.debian.org' ],
        [ 'denis.debian.org', 'diamond.debian.org' ],
-       [ 'denis.debian.org', 'orff.debian.org' ]
+       [ 'denis.debian.org', 'orff.debian.org' ],
+       [ 'denis.debian.org', 'geo1.debian.org' ],
+       [ 'denis.debian.org', 'geo2.debian.org' ],
+       [ 'denis.debian.org', 'geo3.debian.org' ]
        ]
 
 lines = []
@@ -23,7 +24,7 @@ pairs.each do |pair|
 
        key = scope.function_hkdf(['/etc/puppet/secret', "puppet-key-#{keyname}"])
 
-       lines << "key #{keyname} { algorithm hmac-md5; secret \"#{key}\"; };"
+       lines << "key #{keyname} { algorithm hmac-sha256; secret \"#{key}\"; };"
 
        remote_ip = scope.lookupvar('site::allnodeinfo')[other]['ipHostNumber']
        remote_ip.each do |r|