summaryrefslogtreecommitdiff
path: root/manifests/tlspolicy_snippet.pp
blob: 77fc457b5d7537d0368402e606b50e2afd485fba (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
/*
== Definition: postfix::tlspolicy_snippet

Adds a TLS policy snippets to /etc/postfix/tls_policy.
See the postfix::tlspolicy class for details.

Parameters:
- *name*: name of destination domain Postfix will lookup. See TLS_README.
- *value*: right-hand part of the tls_policy map

Requires:
- Class["postfix"]
- Class["postfix::tlspolicy"]

Example usage:

  node "toto.example.com" {
    class { 'postfix':
      manage_tls_policy => 'yes',
    }
    postfix::tlspolicy_snippet {
      'example.com':  value => 'encrypt';
      '.example.com': value => 'encrypt';
      'nothing.com':  value => 'fingerprint match=2A:FF:F0:EC:52:04:99:45:73:1B:C2:22:7F:FD:31:6B:8F:07:43:29';
    }
  }

*/

define postfix::tlspolicy_snippet ($value = false) {

  if $value == false {
    fail("The value parameter must be set when using the postfix::tlspolicy_snippet define.")
  }

  include postfix::tlspolicy

  concat::fragment { "postfix_tlspolicy_${name}":
    content => "${name}		${value}\n",
    target  => "$postfix::tlspolicy::postfix_merged_tlspolicy",
  }

}