summaryrefslogtreecommitdiff
path: root/puppet/modules/unbound/manifests/ssl.pp
diff options
context:
space:
mode:
authorMicah <micah@leap.se>2016-07-12 16:46:10 -0400
committerMicah <micah@leap.se>2016-07-12 16:46:10 -0400
commitf5775156d8d8800247b8917ab6212c7eed16a124 (patch)
treecbfb53e2a37dbc9f5f8132819b9b03d5839d510e /puppet/modules/unbound/manifests/ssl.pp
parent40ea2656f072e23bbbccd22c39fb29a36390fa3a (diff)
git subrepo clone https://leap.se/git/puppet_unbound puppet/modules/unbound
subrepo: subdir: "puppet/modules/unbound" merged: "a26b91d" upstream: origin: "https://leap.se/git/puppet_unbound" branch: "master" commit: "a26b91d" git-subrepo: version: "0.3.0" origin: "https://github.com/ingydotnet/git-subrepo" commit: "1e79595" Change-Id: I83719264de2c716035d34599d541cadd42319b74
Diffstat (limited to 'puppet/modules/unbound/manifests/ssl.pp')
-rw-r--r--puppet/modules/unbound/manifests/ssl.pp25
1 files changed, 25 insertions, 0 deletions
diff --git a/puppet/modules/unbound/manifests/ssl.pp b/puppet/modules/unbound/manifests/ssl.pp
new file mode 100644
index 00000000..e0cff172
--- /dev/null
+++ b/puppet/modules/unbound/manifests/ssl.pp
@@ -0,0 +1,25 @@
+# == Class: unbound::ssl
+#
+# unbound::ssl creates ssl certificates for controlling unbound with unbound-control,
+# using the unbound-control-setup program. Furthermore, the class manages the mode and user of the certificates themselves.
+#
+# === Examples
+#
+# include unbound::ssl
+#
+class unbound::ssl {
+ include unbound::params
+
+ file { $unbound::params::control_certs:
+ owner => $unbound::params::user,
+ group => $unbound::params::gruop,
+ mode => '0440',
+ require => Exec[$unbound::params::control_setup],
+ }
+
+ exec { $unbound::params::control_setup:
+ command => "${unbound::params::control_setup} -d ${unbound::params::dir}",
+ creates => $unbound::params::control_certs,
+ before => Class['unbound::service'],
+ }
+}