Make ssh puppetkeys mode 0444 (instead of 0644)
[mirror/dsa-puppet.git] / modules / ssh / manifests / init.pp
index 56537e4..367cae6 100644 (file)
@@ -9,11 +9,11 @@ class ssh {
                require => Package['openssh-server']
        }
 
-       @ferm::rule { 'dsa-ssh':
+       ferm::rule { 'dsa-ssh':
                description => 'Allow SSH from DSA',
                rule        => '&SERVICE_RANGE(tcp, ssh, $SSH_SOURCES)'
        }
-       @ferm::rule { 'dsa-ssh-v6':
+       ferm::rule { 'dsa-ssh-v6':
                description => 'Allow SSH from DSA',
                domain      => 'ip6',
                rule        => '&SERVICE_RANGE(tcp, ssh, $SSH_V6_SOURCES)'
@@ -33,6 +33,15 @@ class ssh {
                mode    => '0755',
                require => Package['openssh-server']
        }
+       file { '/etc/ssh/puppetkeys':
+               ensure  => directory,
+               mode    => '0755',
+               purge   => true,
+               recurse => true,
+               force   => true,
+               source  => 'puppet:///files/empty/',
+               require => Package['openssh-server']
+       }
        file { '/etc/ssh/userkeys/root':
                content => template('ssh/authorized_keys.erb'),
        }