class roles::rtc {
- ssl::service { 'www.debian.org':
+ ssl::service { 'debian.org':
+ tlsaport => [],
+ notify => Service['repro'],
+ key => true,
}
ssl::service { 'sip-ws.debian.org':
+ key => true,
+ }
+
+ dnsextras::tlsa_record{ 'tlsa-xmpp':
+ zone => 'debian.org',
+ certfile => "/etc/puppet/modules/ssl/files/servicecerts/www.debian.org.crt",
+ port => [5061, 5222, 5269],
+ hostname => $::fqdn,
}
@ferm::rule { 'dsa-xmpp-client-ip4':
file { '/etc/monit/monit.d/50rtc':
ensure => absent,
}
+
+ service { 'repro':
+ ensure => running,
+ }
}