logtest01 spends much of it's time down
[mirror/dsa-puppet.git] / modules / ssh / manifests / init.pp
index b00d774..e2248f8 100644 (file)
@@ -17,7 +17,7 @@ class ssh {
                ensure  => directory,
                owner   => root,
                group   => root,
-               mode    => 775,
+               mode    => 755,
                 ;
               "/etc/ssh/userkeys/root":
                 content => template("ssh/authorized_keys.erb"),
@@ -30,4 +30,14 @@ class ssh {
             path        => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
             refreshonly => true,
         }
+
+        @ferm::rule { "dsa-ssh":
+                description     => "Allow SSH from DSA",
+                rule            => "proto tcp mod state state (NEW) dport (ssh) @subchain 'ssh' { saddr (\$SSH_SOURCES) ACCEPT; }"
+        }
+        @ferm::rule { "dsa-ssh-v6":
+                description     => "Allow SSH from DSA",
+                domain          => "ip6",
+                rule            => "proto tcp mod state state (NEW) dport (ssh) @subchain 'ssh' { saddr (\$SSH_V6_SOURCES) ACCEPT; }"
+        }
 }