add apt-in-chroot to allowed sudo commands
[mirror/dsa-puppet.git] / modules / ssh / manifests / init.pp
index c802efe..98add73 100644 (file)
@@ -30,4 +30,17 @@ class ssh {
             path        => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
             refreshonly => true,
         }
+
+        @ferm::rule { "dsa-ssh":
+                description     => "Allow SSH from DSA",
+                rule            => "&SERVICE_RANGE(tcp, ssh, \$SSH_SOURCES)"
+        }
+        @ferm::rule { "dsa-ssh-v6":
+                description     => "Allow SSH from DSA",
+                domain          => "ip6",
+                rule            => "&SERVICE_RANGE(tcp, ssh, \$SSH_V6_SOURCES)"
+        }
 }
+# vim:set et:
+# vim:set sts=4 ts=4:
+# vim:set shiftwidth=4: