summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMicah Anderson <micah@leap.se>2013-09-26 17:20:19 -0400
committerMicah Anderson <micah@leap.se>2013-10-02 12:47:11 -0400
commitf531ec536a55d756262329f516f1b3bdccf4f0b4 (patch)
tree3726abe647efc98aacf8448409a6bd6d20b50593
parent62271e0e067daef064dba2860a92eb6351510d3c (diff)
setup smtpd_tls_eecdh_grade to 'ultra' and configure the smtpd_tls_dh1024_param file, after generating it (#3953)
Change-Id: I8e88a4862cda052c2f0ca0149f1d0753c7c83cb5
-rw-r--r--puppet/modules/site_postfix/manifests/mx/tls.pp31
1 files changed, 31 insertions, 0 deletions
diff --git a/puppet/modules/site_postfix/manifests/mx/tls.pp b/puppet/modules/site_postfix/manifests/mx/tls.pp
index 34df72bb..9122a974 100644
--- a/puppet/modules/site_postfix/manifests/mx/tls.pp
+++ b/puppet/modules/site_postfix/manifests/mx/tls.pp
@@ -14,6 +14,37 @@ class site_postfix::mx::tls {
'smtpd_tls_ask_ccert': value => 'yes';
'smtpd_tls_security_level':
value => 'may';
+ 'smtpd_tls_eecdh_grade':
+ value => 'ultra'
+ }
+
+ # Setup DH parameters
+ # Instead of using the dh parameters that are created by leap cli, it is more
+ # secure to generate new parameter files that will only be used for postfix,
+ # for each machine
+
+ include site_config::packages::gnutls
+
+ exec { 'certtool-postfix-gendh-1024':
+ command => 'certtool --generate-dh-params --bits=1024 --outfile=/etc/postfix/dh_1024.pem',
+ user => root,
+ group => root,
+ creates => '/etc/postfix/dh_1024.pem',
+ require => Package['gnutls-bin']
+ }
+
+ # Make sure the dh params file has correct ownership and mode
+ file {
+ '/etc/postfix/dh_1024.pem':
+ owner => root,
+ group => root,
+ mode => '0600',
+ require => Exec['certtool-postfix-gendh-1024'];
+ }
+
+ postfix::config { 'smtpd_tls_dh1024_param_file':
+ value => '/etc/postfix/dh_1024.pem',
+ require => File['/etc/postfix/dh_1024.pem']
}
}