From 2770088f3b3b54ca45a402e34b7f688b78c632e0 Mon Sep 17 00:00:00 2001 From: Peter Palfrader Date: Thu, 5 Nov 2015 19:55:40 +0100 Subject: [PATCH] maybe TLSA records for XMPP stuff --- modules/roles/manifests/rtc.pp | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/modules/roles/manifests/rtc.pp b/modules/roles/manifests/rtc.pp index 754367043..045607597 100644 --- a/modules/roles/manifests/rtc.pp +++ b/modules/roles/manifests/rtc.pp @@ -6,6 +6,13 @@ class roles::rtc { ssl::service { 'sip-ws.debian.org': } + dnsextras::tlsa_record{ 'tlsa-xmpp': + zone => 'debian.org', + certfile => "/etc/puppet/modules/ssl/files/servicecerts/www.debian.org.crt", + port => [5061, 5222, 5269], + hostname => $::fqdn, + } + @ferm::rule { 'dsa-xmpp-client-ip4': domain => 'ip', description => 'XMPP connections (client to server)', -- 2.20.1