X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;ds=sidebyside;f=modules%2Fssl%2Fmanifests%2Fservice.pp;h=a9d4fd45b1bddba88e3cff4e2ce0496138a79d4b;hb=030ce8b3edff0fc9311d83cdfe9ba2735aee5221;hp=5c2509af1e82cfac6ed384916f69fa8210b3be3b;hpb=d49c5681d5da614ccc27ff96e91e9aa2bcee20c1;p=mirror%2Fdsa-puppet.git diff --git a/modules/ssl/manifests/service.pp b/modules/ssl/manifests/service.pp index 5c2509af1..a9d4fd45b 100644 --- a/modules/ssl/manifests/service.pp +++ b/modules/ssl/manifests/service.pp @@ -1,4 +1,4 @@ -define ssl::service($ensure = present, $tlsaport = 443, $notify = []) { +define ssl::service($ensure = present, $tlsaport = 443, $notify = [], $key = false) { $link_target = $ensure ? { present => link, absent => absent, @@ -6,23 +6,32 @@ define ssl::service($ensure = present, $tlsaport = 443, $notify = []) { } file { "/etc/ssl/debian/certs/$name.crt": - source => "puppet:///modules/ssl/servicecerts/${name}.crt", + source => [ "puppet:///modules/ssl/servicecerts/${name}.crt", "puppet:///modules/ssl/from-letsencrypt/${name}.crt" ], notify => [ Exec['refresh_debian_hashes'], $notify ], } file { "/etc/ssl/debian/certs/$name.crt-chain": - source => [ "puppet:///modules/ssl/chains/${name}.crt", "puppet:///modules/ssl/servicecerts/${name}.crt" ], - notify => [ Exec['refresh_debian_hashes'], $notify ], + source => [ "puppet:///modules/ssl/chains/${name}.crt", "puppet:///modules/ssl/servicecerts/${name}.crt", "puppet:///modules/ssl/from-letsencrypt/${name}.crt-chain" ], + notify => [ $notify ], links => follow, } file { "/etc/ssl/debian/certs/$name.crt-chained": content => template('ssl/chained.erb'), - notify => [ Exec['refresh_debian_hashes'], $notify ], + notify => [ $notify ], + } + if $key { + file { "/etc/ssl/private/$name.key": + mode => '0440', + group => 'ssl-cert', + source => [ "puppet:///modules/ssl/keys/${name}.crt", "puppet:///modules/ssl/from-letsencrypt/${name}.key" ], + notify => [ $notify ], + links => follow, + } } if $tlsaport > 0 { dnsextras::tlsa_record{ "tlsa-${name}-${tlsaport}": zone => 'debian.org', - certfile => "/etc/puppet/modules/ssl/files/servicecerts/${name}.crt", + certfile => [ "/etc/puppet/modules/ssl/files/servicecerts/${name}.crt", "/etc/puppet/modules/ssl/files/from-letsencrypt/${name}.crt" ], port => $tlsaport, hostname => "$name", }