Danger, Will Robinson. We need to create etc/ssh/userkeys - else we lock ourselves...
[mirror/dsa-puppet.git] / modules / ssh / manifests / init.pp
index 75fb475..b00d774 100644 (file)
@@ -10,7 +10,24 @@ class ssh {
                 ;
               "/etc/ssh/sshd_config":
                content => template("ssh/sshd_config.erb"),
-               require => Package["openssh-server"]
+               require => Package["openssh-server"],
+                notify  => Exec["ssh restart"]
+                ;
+              "/etc/ssh/userkeys":
+               ensure  => directory,
+               owner   => root,
+               group   => root,
+               mode    => 775,
+                ;
+              "/etc/ssh/userkeys/root":
+                content => template("ssh/authorized_keys.erb"),
+                mode    => 444,
+                require => Package["openssh-server"]
                 ;
        }
+
+        exec { "ssh restart":
+            path        => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
+            refreshonly => true,
+        }
 }