X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Froles%2Fmanifests%2Frtc.pp;h=b488e45ea3763050e39a0f8c6efc28aa6ac8a591;hb=48a7fe9cc927439d6e472b1b9939f72a4a7f4aa8;hp=754367043d9f6cce19d482fcea731aa27eb783b3;hpb=7979d10744f00844e4dcaaefe1a4fa5debf57b3e;p=mirror%2Fdsa-puppet.git diff --git a/modules/roles/manifests/rtc.pp b/modules/roles/manifests/rtc.pp index 754367043..b488e45ea 100644 --- a/modules/roles/manifests/rtc.pp +++ b/modules/roles/manifests/rtc.pp @@ -1,9 +1,21 @@ class roles::rtc { - ssl::service { 'www.debian.org': + ssl::service { 'debian.org': + tlsaport => [], + notify => Service['repro'], + key => true, } ssl::service { 'sip-ws.debian.org': + notify => Service['repro'], + key => true, + } + + dnsextras::tlsa_record{ 'tlsa-xmpp': + zone => 'debian.org', + certfile => "/etc/puppet/modules/ssl/files/servicecerts/www.debian.org.crt", + port => [5061, 5222, 5269], + hostname => $::fqdn, } @ferm::rule { 'dsa-xmpp-client-ip4': @@ -81,4 +93,8 @@ class roles::rtc { file { '/etc/monit/monit.d/50rtc': ensure => absent, } + + service { 'repro': + ensure => running, + } }