ensure our tsig keys are protected
[mirror/dsa-puppet.git] / modules / named / manifests / secondary.pp
index 003f1fe..8d00d0a 100644 (file)
@@ -4,5 +4,10 @@ class named::secondary inherits named {
                      "puppet:///named/common/named.conf.debian-zones" ],
         notify  => Exec["bind9 reload"],
     }
+    file { "/etc/bind/named.conf.shared-keys":
+        mode    => 640,
+        owner   => root,
+        group   => bind,
+    }
 }