<feed xmlns='http://www.w3.org/2005/Atom'>
<title>leap_platform.git/puppet/modules/site_openvpn/manifests, branch 0.6.0rc1</title>
<subtitle>[leap_platform] 
</subtitle>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/'/>
<entry>
<title>Make sure openvpn is restarted when cert/key change (#6405)</title>
<updated>2014-11-20T20:31:27+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-11-20T20:31:27+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=dff949811324215278ab7e4c2db5de63d8a6218b'/>
<id>dff949811324215278ab7e4c2db5de63d8a6218b</id>
<content type='text'>
I reformatted the section below for consistency.

Change-Id: I18f5e23850e0c1ab4b1f2ee467d5af54ae9ff303
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
I reformatted the section below for consistency.

Change-Id: I18f5e23850e0c1ab4b1f2ee467d5af54ae9ff303
</pre>
</div>
</content>
</entry>
<entry>
<title>openvpn - support customizing --fragment, and set default to 1400</title>
<updated>2014-11-11T04:43:24+00:00</updated>
<author>
<name>elijah</name>
<email>elijah@riseup.net</email>
</author>
<published>2014-11-11T04:43:24+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=b9d2030beb890e8dccbbe42bfcc430a2c2702a92'/>
<id>b9d2030beb890e8dccbbe42bfcc430a2c2702a92</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>fix unbound: configs in /etc/unbound/unbound.conf.d contained a syntax error and were missing .conf suffix</title>
<updated>2014-06-02T18:03:56+00:00</updated>
<author>
<name>elijah</name>
<email>elijah@riseup.net</email>
</author>
<published>2014-06-02T18:03:56+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=09916946f8eb0ab17689255fd626a52ef1808e6a'/>
<id>09916946f8eb0ab17689255fd626a52ef1808e6a</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Implement #2328: unbound.conf: content changed on every puppetrun</title>
<updated>2014-05-22T19:50:02+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-05-22T19:21:06+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=a622e49c5df2150049afb6f6ed47177537b7e6da'/>
<id>a622e49c5df2150049afb6f6ed47177537b7e6da</id>
<content type='text'>
This is done by using the include glob capability that is in the
wheezy-backports and newer unbound to include the
/etc/unbound/unbound.conf.d/* config files.

To do this, we need to transition from our /etc/unbound/conf.d directory
structure to use the one that the debian package uses.

This allows us to clean up the rather ugly way we were configuring the
resolver before.

Change-Id: I68347922f265bbd0ddf11d59d8574a612a7bd82c
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This is done by using the include glob capability that is in the
wheezy-backports and newer unbound to include the
/etc/unbound/unbound.conf.d/* config files.

To do this, we need to transition from our /etc/unbound/conf.d directory
structure to use the one that the debian package uses.

This allows us to clean up the rather ugly way we were configuring the
resolver before.

Change-Id: I68347922f265bbd0ddf11d59d8574a612a7bd82c
</pre>
</div>
</content>
</entry>
<entry>
<title>openvpn server config: script-security should be "1", since we don't need "2"; add tcp-nodelay to tcp servers.</title>
<updated>2014-05-13T09:22:05+00:00</updated>
<author>
<name>elijah</name>
<email>elijah@riseup.net</email>
</author>
<published>2014-05-13T09:22:05+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=3ef044034b51d992d6952a9c6b9d16cba16abc30'/>
<id>3ef044034b51d992d6952a9c6b9d16cba16abc30</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>openvpn package resource needs to be ensure =&gt; latest to accommodate upgrades</title>
<updated>2014-05-07T17:32:00+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-05-07T17:32:00+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=a980840e5752296c772ec079bbfc0ecb2c3d331f'/>
<id>a980840e5752296c772ec079bbfc0ecb2c3d331f</id>
<content type='text'>
Change-Id: I8caad9b4ac15dcce8ab74ad6d22dd6ad9f6efb14
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I8caad9b4ac15dcce8ab74ad6d22dd6ad9f6efb14
</pre>
</div>
</content>
</entry>
<entry>
<title>set the ipv6 configuration options on the server</title>
<updated>2014-05-06T20:33:02+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-05-06T20:33:02+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=0265eb952691ee91405201836e19384ac2087507'/>
<id>0265eb952691ee91405201836e19384ac2087507</id>
<content type='text'>
some important things to note:

We are hard-coding the pushing of the ipv6 route '2000::/3' and
configuring the server-ipv6 to be 2001:db8:123::/64. This netblock is a
reserved ipv6 prefix that is used for documentation purposes
only (http://www.apnic.net/info/faq/ipv6-documentation-prefix-faq.html),
and the route being pushed redirects all internet-bound traffic.

When LEAP fully supports ipv6, these network values should be turned
into variables, but for now, to make sure we are blocking any clients
that have functional ipv6, this will work.

Change-Id: Icb65f3169264e0178a2e98825b266a779feac6b5
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
some important things to note:

We are hard-coding the pushing of the ipv6 route '2000::/3' and
configuring the server-ipv6 to be 2001:db8:123::/64. This netblock is a
reserved ipv6 prefix that is used for documentation purposes
only (http://www.apnic.net/info/faq/ipv6-documentation-prefix-faq.html),
and the route being pushed redirects all internet-bound traffic.

When LEAP fully supports ipv6, these network values should be turned
into variables, but for now, to make sure we are blocking any clients
that have functional ipv6, this will work.

Change-Id: Icb65f3169264e0178a2e98825b266a779feac6b5
</pre>
</div>
</content>
</entry>
<entry>
<title>install openvpn from wheezy-backports, this will bring in openvpn 2.3,</title>
<updated>2014-05-06T20:32:28+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-05-06T20:32:28+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=f63f302980d638633f0bdb1146f9d8a75e9eaed2'/>
<id>f63f302980d638633f0bdb1146f9d8a75e9eaed2</id>
<content type='text'>
which will provide us with proper ipv6 support

Change-Id: I0188732aae6cbc64ab57e95bf805d6158fa17e07
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
which will provide us with proper ipv6 support

Change-Id: I0188732aae6cbc64ab57e95bf805d6158fa17e07
</pre>
</div>
</content>
</entry>
<entry>
<title>make sure concat fragments are put together before the openvpn service</title>
<updated>2014-04-24T16:05:11+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-04-24T16:05:11+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=b5245481bbc1fddfd1b8e6d97e8a07a20d35de6b'/>
<id>b5245481bbc1fddfd1b8e6d97e8a07a20d35de6b</id>
<content type='text'>
is run, otherwise the openvpn service is restarted before config files
are deployed (#4154)

Change-Id: Ide38615714c1978bb90237986baea530c54153c3
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
is run, otherwise the openvpn service is restarted before config files
are deployed (#4154)

Change-Id: Ide38615714c1978bb90237986baea530c54153c3
</pre>
</div>
</content>
</entry>
<entry>
<title>update indentation to be standard</title>
<updated>2014-04-24T16:04:20+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-04-24T16:04:20+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=98227ad8da45544ef97cb8647c377f399672a4a0'/>
<id>98227ad8da45544ef97cb8647c377f399672a4a0</id>
<content type='text'>
Change-Id: Ic0ac3a7e6c9ce0e5f95bab023dbbf890c31d9e1c
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: Ic0ac3a7e6c9ce0e5f95bab023dbbf890c31d9e1c
</pre>
</div>
</content>
</entry>
</feed>
