openssh-server: ensure => installed;
}
- case $hostname {
- bartok: {
- $keyinfo = allnodeinfo("sshRSAHostKey", "ipHostNumber")
- }
- }
-
-
file { "/etc/ssh/ssh_config":
- source => [ "puppet:///ssh/ssh_config" ],
+ content => template("ssh/ssh_config.erb"),
require => Package["openssh-client"]
;
"/etc/ssh/sshd_config":
path => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
refreshonly => true,
}
+
+ @ferm::rule { "dsa-ssh":
+ description => "Allow SSH from DSA",
+ rule => "&SERVICE_RANGE(tcp, ssh, \$SSH_SOURCES)"
+ }
+ @ferm::rule { "dsa-ssh-v6":
+ description => "Allow SSH from DSA",
+ domain => "ip6",
+ rule => "&SERVICE_RANGE(tcp, ssh, \$SSH_V6_SOURCES)"
+ }
}
+# vim:set et:
+# vim:set sts=4 ts=4:
+# vim:set shiftwidth=4: