]> git.donarmstrong.com Git - dsa-puppet.git/commitdiff
restart stunnel regularly
authorPeter Palfrader <peter@palfrader.org>
Tue, 24 May 2011 10:11:19 +0000 (12:11 +0200)
committerPeter Palfrader <peter@palfrader.org>
Tue, 24 May 2011 10:11:19 +0000 (12:11 +0200)
modules/entropykey/manifests/init.pp

index 13de3e4ea915e9c1006a825c4f9f1eb704839c33..e9c612657b03becddc992ae1da0bcfc784ffdd3f 100644 (file)
@@ -8,6 +8,13 @@ class entropykey::provider {
             source => "puppet:///modules/entropykey/ekeyd.conf",
             notify  => Exec['restart_ekeyd'],
             require => [ Package['ekeyd'] ],
+            ;
+        # our CRL expires after a while (2 or 4 weeks?), so we have
+        # to restart stunnel so it loads the new CRL.
+        "/etc/cron.weekly/stunnel-ekey.conf":
+            content =>  "# This file is under puppet control\nenv -i /etc/init.d/stunnel4 restart puppet-ekeyd\n",
+            mode => "555",
+            ;
         ;
     }