diff options
| author | varac <varacanero@zeromail.org> | 2014-02-13 08:46:52 +0100 | 
|---|---|---|
| committer | varac <varacanero@zeromail.org> | 2014-02-13 08:46:52 +0100 | 
| commit | 234d9fdf88d95db79c9d5983af8e0c318edb28c7 (patch) | |
| tree | 0f85df350d582024bc2aa870711285325fc96bea /puppet/modules | |
| parent | 251c250fe5cf44c99a74d4359cb29b0bf165f3af (diff) | |
| parent | 0b3e87cd6916d4ca4404fd2b375d21468d17f343 (diff) | |
Merge remote-tracking branch 'elijah/feature/known_hosts' into fix_develop
Diffstat (limited to 'puppet/modules')
| -rw-r--r-- | puppet/modules/site_sshd/manifests/init.pp | 18 | ||||
| -rw-r--r-- | puppet/modules/site_sshd/templates/ssh_config.erb | 23 | ||||
| -rw-r--r-- | puppet/modules/site_sshd/templates/ssh_known_hosts.erb | 7 | 
3 files changed, 48 insertions, 0 deletions
| diff --git a/puppet/modules/site_sshd/manifests/init.pp b/puppet/modules/site_sshd/manifests/init.pp index 90dd2d0e..2bcde603 100644 --- a/puppet/modules/site_sshd/manifests/init.pp +++ b/puppet/modules/site_sshd/manifests/init.pp @@ -1,5 +1,6 @@  class site_sshd {    $ssh = hiera_hash('ssh') +  $hosts = hiera_hash('hosts')    ##    ## SETUP AUTHORIZED KEYS @@ -12,6 +13,23 @@ class site_sshd {    }    ## +  ## SETUP KNOWN HOSTS and SSH_CONFIG +  ## + +  file { +    '/etc/ssh/ssh_known_hosts': +      owner   => root, +      group   => root, +      mode    => '0644', +      content => template('site_sshd/ssh_known_hosts.erb'); +    '/etc/ssh/ssh_config': +      owner => root, +      group => root, +      mode => '0644', +      content => template('site_sshd/ssh_config.erb'); +  } + +  ##    ## OPTIONAL MOSH SUPPORT    ## diff --git a/puppet/modules/site_sshd/templates/ssh_config.erb b/puppet/modules/site_sshd/templates/ssh_config.erb new file mode 100644 index 00000000..7e967413 --- /dev/null +++ b/puppet/modules/site_sshd/templates/ssh_config.erb @@ -0,0 +1,23 @@ +# This file is generated by Puppet +# This is the ssh client system-wide configuration file.  See +# ssh_config(5) for more information.  This file provides defaults for +# users, and the values can be changed in per-user configuration files +# or on the command line. + +Host * +    SendEnv LANG LC_* +    HashKnownHosts yes +    GSSAPIAuthentication yes +    GSSAPIDelegateCredentials no +<% if scope.lookupvar('::site_config::params::environment') == 'local' -%> +    # +    # Vagrant nodes should have strict host key checking +    # turned off. The problem is that the host key for a vagrant +    # node is specific to the particular instance of the vagrant +    # node you have running locally. For this reason, we can't +    # track the host keys, or your host key for vpn1 would conflict +    # with my host key for vpn1. +    # +    StrictHostKeyChecking no +<% end -%> + diff --git a/puppet/modules/site_sshd/templates/ssh_known_hosts.erb b/puppet/modules/site_sshd/templates/ssh_known_hosts.erb new file mode 100644 index 00000000..002ab732 --- /dev/null +++ b/puppet/modules/site_sshd/templates/ssh_known_hosts.erb @@ -0,0 +1,7 @@ +# This file is generated by Puppet + +<% @hosts.sort.each do |name, hash| -%> +<%   if hash['host_pub_key'] -%> +<%=    name%>,<%=hash['domain_full']%>,<%=hash['domain_internal']%>,<%=hash['ip_address']%> <%=hash['host_pub_key']%> +<%   end -%> +<% end -%> | 
