]> gitweb.fluxo.info Git - puppet-nodo.git/commitdiff
Use ENC for sshd params
authorSilvio Rhatto <rhatto@riseup.net>
Mon, 28 Mar 2016 17:39:21 +0000 (14:39 -0300)
committerSilvio Rhatto <rhatto@riseup.net>
Mon, 28 Mar 2016 17:39:21 +0000 (14:39 -0300)
manifests/subsystem/sshd.pp

index 6650fb9de4ef6934a849a7e18a10d0289559c0b1..3327de8023dbfced0adef104f0e86598cab6274b 100644 (file)
@@ -1,22 +1,5 @@
 class nodo::subsystem::sshd {
-  # SSH Server
-  #
-  # We need to restrict listen address by default so multiple
-  # instances can live together in the same physical host.
-  #
-  class { '::sshd':
-    manage_nagios           => hiera('nodo::subsystem::sshd::manage_nagios',           false),      
-    listen_address          => hiera('nodo::subsystem::sshd::listen_address',          [ "${::ipaddress}", '127.0.0.1' ]),
-    password_authentication => hiera('nodo::subsystem::sshd::password_authentication', 'yes'),
-    shared_ip               => hiera('nodo::subsystem::sshd::shared_ip',               'yes'),
-    tcp_forwarding          => hiera('nodo::subsystem::sshd::tcp_forwarding',          'yes'),
-    x11_forwarding          => hiera('nodo::subsystem::sshd::x11_forwarding',          'no'),
-    hardened                => hiera('nodo::subsystem::sshd::hardened',                'yes'),
-    print_motd              => hiera('nodo::subsystem::sshd::print_motd',              'no'),
-    ports                   => hiera('nodo::subsystem::sshd::ports',                   [ 22 ]),
-    use_pam                 => hiera('nodo::subsystem::sshd::use_pam',                 'no'),
-    use_storedconfigs       => hiera('nodo::subsystem::use_storedconfigs',             false),
-  }
+  include ::sshd
 
   # Add the localhost ssh key, useful when one needs
   # to ssh to localhost.