summaryrefslogtreecommitdiff
AgeCommit message (Expand)Author
2013-09-18use x509 for postfix ca and fix names for cert+key (Feature #3833)varac
2013-09-18deploy client_ca (#3833)varac
2013-09-18Include content of client_ca.crt and client_ca.key in hiera (Feature #3874)varac
2013-09-18openvpn should use /usr/local/share/ca-certificates/leap_ca.crt (Feature #3831)varac
2013-09-18include shorewall::interface{eth0} in setup.pp so packages can be installed d...varac
2013-09-17fix stunnel module so that code was not removed accidentallyMicah Anderson
2013-09-17Merge branch 'feature/2399_shorewall_on_vagrant_fails' into developvarac
2013-09-17shorewall: #2399 blocks uplink (Bug #2866)varac
2013-09-17site_config::params::interface should contain eth1 for vagrant cause it's the...varac
2013-09-17update stunnel submodule commit id to correct one for new repositoryMicah Anderson
2013-09-17Merge branch 'bug/3757' into developMicah Anderson
2013-09-17updated submodule stunnel - include stunnel in stunnel::service (https://leap...varac
2013-09-17Merge branch 'feature/3817_3836_3837_Duplicate_declarations' into developvarac
2013-09-14ensure site_config::caching_resolver runs with tag leap_base (#3757)Micah Anderson
2013-09-14moved openvpn submodule back to 25f1fe8d8, like it was beforekwadronaut
2013-09-14Merge branch 'vcs_module' into developkwadronaut
2013-09-13change vcsrepo submodule url (bug #3139)kwadronaut
2013-09-13change openvpn submodule url (bug #3139)kwadronaut
2013-09-13setup stunnel config to use default x509 cert,key+ca (#3837)varac
2013-09-13Deploy default x509 cert + key that services can use (Feature #3836)varac
2013-09-13remove x509::ca for leap_ca in site_openvpn::keys and site_stunnel::stunnel (...varac
2013-09-13deploy default x509::ca leap_ca in site_config::default (#3817)varac
2013-09-13use define instead of class for site_stunnel::setup (#3817)varac
2013-09-05make sure we gather ec2_public_ipv4 fact. REQUIRES latest leap_cli (1.2.2)elijah
2013-09-05require that shorewall is up before running bundler commands, it needs to pul...0.3.0rc1Micah Anderson
2013-09-05updated submodule apt: unattended-upgrades package cannot be installed (Bug #...varac
2013-09-05Merge branch 'feature/3747_puppet_fails_if_no_services_are_configured' into d...varac
2013-09-05Some packages are installed before refresh_apt is called (Bug #2988)varac
2013-09-05puppet fails if no services are configured (Bug #3747)varac
2013-09-04fix initial firewall to allow outgoing lo traffic and outgoing port 443 (#3736)Micah Anderson
2013-09-04change git repository clone URIs from git:// to https:// (#3732)Micah Anderson
2013-09-04need to test that /etc/init.d/shorewall exists before attempting to call it, ...Micah Anderson
2013-09-04updated couchdb submodule: bigcouch nodes doesn't get registered as cluster m...varac
2013-09-04Merge branch 'bug/3339' into developMicah Anderson
2013-09-04fix soledad-server not being available before the leap repository has been co...Micah Anderson
2013-09-04make sure that the shorewall package is installed before trying to change its...Micah Anderson
2013-09-04updated submodule couchdb: don't use couchdb::document for creating _security...varac
2013-09-03Work around for shorewall not being available at the site_config stage (#3339)Micah Anderson
2013-09-03Merge branch 'feature/3667_Sending_mail_fails_when_relaying_using_non-fully-q...varac
2013-09-03use check_helo_access hash:/helo_checks also for $submission_helo_restrictionsvarac
2013-09-03fix $master_cf_tail formatvarac
2013-09-03Sending mail fails when relaying using non-fully-qualified hostname (Feature ...varac
2013-09-03Merge branch 'feature/helo_access' into developMicah Anderson
2013-09-03Merge branch 'bug/3339' into developMicah Anderson
2013-09-03add /etc/postfix/checks directory and setup a check_helo_access that allows a...Micah Anderson
2013-09-03require that shorewall has been installed before execs are run (#3339)Micah Anderson
2013-09-03require that shorewall has been installed before execs are run (#3339)Micah Anderson
2013-09-03Without smtpd_helo_required, the helo restrictions are easily bypassed by not...Micah Anderson
2013-09-02disable postfix debugging by defaultvarac
2013-09-02create all webapp databases so _security is set (fixes 3517)Azul