3 openssh-client: ensure => installed;
4 openssh-server: ensure => installed;
7 file { "/etc/ssh/ssh_config":
8 source => [ "puppet:///ssh/ssh_config" ],
9 require => Package["openssh-client"]
11 "/etc/ssh/sshd_config":
12 content => template("ssh/sshd_config.erb"),
13 require => Package["openssh-server"],
14 notify => Exec["ssh restart"]
22 "/etc/ssh/userkeys/root":
23 content => template("ssh/authorized_keys.erb"),
25 require => Package["openssh-server"]
30 path => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
34 @ferm::rule { "dsa-ssh":
35 description => "Allow SSH from DSA",
36 rule => "proto tcp mod state state (NEW) dport (ssh) @subchain 'ssh' { saddr (\$SSH_SOURCES) ACCEPT; }"
38 @ferm::rule { "dsa-ssh-v6":
39 description => "Allow SSH from DSA",
41 rule => "proto tcp mod state state (NEW) dport (ssh) @subchain 'ssh' { saddr (\$SSH_V6_SOURCES) ACCEPT; }"