projects
/
mirror
/
dsa-puppet.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
Create shared TSIG keys between denis and geo[123]
[mirror/dsa-puppet.git]
/
modules
/
named
/
templates
/
named.conf.puppet-shared-keys.erb
diff --git
a/modules/named/templates/named.conf.puppet-shared-keys.erb
b/modules/named/templates/named.conf.puppet-shared-keys.erb
index
07172b1
..
be4f011
100644
(file)
--- a/
modules/named/templates/named.conf.puppet-shared-keys.erb
+++ b/
modules/named/templates/named.conf.puppet-shared-keys.erb
@@
-9,7
+9,10
@@
pairs = [
[ 'denis.debian.org', 'ravel.debian.org' ],
[ 'denis.debian.org', 'senfl.debian.org' ],
[ 'denis.debian.org', 'diamond.debian.org' ],
[ 'denis.debian.org', 'ravel.debian.org' ],
[ 'denis.debian.org', 'senfl.debian.org' ],
[ 'denis.debian.org', 'diamond.debian.org' ],
- [ 'denis.debian.org', 'orff.debian.org' ]
+ [ 'denis.debian.org', 'orff.debian.org' ],
+ [ 'denis.debian.org', 'geo1.debian.org' ],
+ [ 'denis.debian.org', 'geo2.debian.org' ],
+ [ 'denis.debian.org', 'geo3.debian.org' ]
]
lines = []
]
lines = []
@@
-21,13
+24,13
@@
pairs.each do |pair|
pair.delete(fqdn)
other = pair[0]
pair.delete(fqdn)
other = pair[0]
- key =
hkdf('/etc/puppet/secret', "puppet-key-#{keyname}"
)
+ key =
scope.function_hkdf(['/etc/puppet/secret', "puppet-key-#{keyname}"]
)
- lines << "key #{keyname} { algorithm hmac-
md5; secret \"#{key}\"; };\n
"
+ lines << "key #{keyname} { algorithm hmac-
sha256; secret \"#{key}\"; };
"
remote_ip = scope.lookupvar('site::allnodeinfo')[other]['ipHostNumber']
remote_ip.each do |r|
remote_ip = scope.lookupvar('site::allnodeinfo')[other]['ipHostNumber']
remote_ip.each do |r|
- lines << "server #{r} { keys { #{keyname}; }; };
\n
"
+ lines << "server #{r} { keys { #{keyname}; }; };"
end
lines << ""
end
end
lines << ""
end