]> gitweb.fluxo.info Git - puppet-sshd.git/log
puppet-sshd.git
15 years agonagios-cmd is now check_ssh_port - according to shared-nagios
nadir [Tue, 5 Oct 2010 17:07:24 +0000 (19:07 +0200)]
nagios-cmd is now check_ssh_port - according to shared-nagios

15 years agoSimplify by using the config_file definition.
intrigeri [Mon, 4 Oct 2010 20:03:49 +0000 (22:03 +0200)]
Simplify by using the config_file definition.

15 years agoAdd template for Debian Squeeze.
intrigeri [Sun, 3 Oct 2010 17:56:48 +0000 (19:56 +0200)]
Add template for Debian Squeeze.

15 years agoActually allow enabling ChallengeResponseAuthentication on Debian Lenny.
intrigeri [Sun, 3 Oct 2010 17:56:04 +0000 (19:56 +0200)]
Actually allow enabling ChallengeResponseAuthentication on Debian Lenny.

15 years agoUsing sshd::client::debian for ubuntu
Silvio Rhatto [Fri, 4 Jun 2010 02:29:10 +0000 (23:29 -0300)]
Using sshd::client::debian for ubuntu

15 years agoAdding Ubuntu_lucid.erb
Silvio Rhatto [Tue, 18 May 2010 23:30:50 +0000 (20:30 -0300)]
Adding Ubuntu_lucid.erb

15 years agoMerge branch 'master' of git://labs.riseup.net/module_sshd
Silvio Rhatto [Thu, 25 Feb 2010 17:52:32 +0000 (14:52 -0300)]
Merge branch 'master' of git://labs.riseup.net/module_sshd

15 years agoupdate nagios check_command to check ssh port. it was using ssh_port, it should be...
Micah Anderson [Sun, 21 Feb 2010 19:01:35 +0000 (14:01 -0500)]
update nagios check_command to check ssh port. it was using ssh_port, it should be 'check_ssh_port'

16 years agoRenaming $sshd_internal_ip to $sshd_shared_ip
Silvio Rhatto [Sat, 30 Jan 2010 23:32:12 +0000 (21:32 -0200)]
Renaming $sshd_internal_ip to $sshd_shared_ip

16 years agoMerge branch 'master' of git://labs.riseup.net/module_sshd
Silvio Rhatto [Mon, 28 Dec 2009 13:18:54 +0000 (11:18 -0200)]
Merge branch 'master' of git://labs.riseup.net/module_sshd

16 years agoMerge remote branch 'lavamind/master'
Micah Anderson [Sun, 27 Dec 2009 21:27:20 +0000 (16:27 -0500)]
Merge remote branch 'lavamind/master'

16 years agoReverting last change
Silvio Rhatto [Sun, 27 Dec 2009 19:04:12 +0000 (17:04 -0200)]
Reverting last change

16 years agoAlways including sshd::client::base
Silvio Rhatto [Sun, 27 Dec 2009 18:53:19 +0000 (16:53 -0200)]
Always including sshd::client::base

16 years agoUsing fqdn instead of hostname.domain
Silvio Rhatto [Sun, 27 Dec 2009 18:30:14 +0000 (16:30 -0200)]
Using fqdn instead of hostname.domain

16 years agoUsing sshrsakey instead of sshrsakey_key
Silvio Rhatto [Sun, 27 Dec 2009 17:33:35 +0000 (15:33 -0200)]
Using sshrsakey instead of sshrsakey_key

16 years agoIntroducing sshd_internal_ip variable
Silvio Rhatto [Sun, 27 Dec 2009 16:23:51 +0000 (14:23 -0200)]
Introducing sshd_internal_ip variable

16 years agoPrintMotd using default OpenSSH setting
Silvio Rhatto [Sun, 27 Dec 2009 16:01:55 +0000 (14:01 -0200)]
PrintMotd using default OpenSSH setting

16 years agoupdate comments to include information about how to use the nagios
Micah Anderson [Mon, 21 Dec 2009 20:00:10 +0000 (15:00 -0500)]
update comments to include information about how to use the nagios
checks and the pre-requirements

16 years agofix the comments section so that the include isn't misleading. if you
Micah Anderson [Sat, 19 Dec 2009 08:30:16 +0000 (03:30 -0500)]
fix the comments section so that the include isn't misleading. if you
use 'include sshd::debian', then none of the variables are set, and you
will fail to parse the templates

16 years agoremove fqdn from nagios service description (hostname is used in the internal nagios_...
Jerome Charaoui [Fri, 18 Dec 2009 19:38:01 +0000 (14:38 -0500)]
remove fqdn from nagios service description (hostname is used in the internal nagios_service name)

16 years agomake key removal a bit easier
mh [Fri, 18 Dec 2009 18:06:43 +0000 (19:06 +0100)]
make key removal a bit easier

16 years agoenable that ssh auth-keys can be removed
mh [Fri, 18 Dec 2009 17:36:05 +0000 (18:36 +0100)]
enable that ssh auth-keys can be removed

16 years agofalse != 'false'
mh [Fri, 11 Dec 2009 08:45:35 +0000 (09:45 +0100)]
false != 'false'

16 years agoset protocol 2 for centos, required.
mh [Fri, 11 Dec 2009 08:35:34 +0000 (09:35 +0100)]
set protocol 2 for centos, required.

16 years agorequire class instead of requiring packages
mh [Thu, 10 Dec 2009 22:49:32 +0000 (23:49 +0100)]
require class instead of requiring packages

16 years agore-add shorewall in rule :/
mh [Thu, 10 Dec 2009 22:45:12 +0000 (23:45 +0100)]
re-add shorewall in rule :/

16 years agoundef or '' as default
mh [Thu, 10 Dec 2009 22:34:57 +0000 (23:34 +0100)]
undef or '' as default

16 years agomerged with riseup module, various cleaning up
mh [Thu, 10 Dec 2009 22:15:07 +0000 (23:15 +0100)]
merged with riseup module, various cleaning up

16 years agomove plugin directory to fit new 0.25 style
mh [Sat, 31 Oct 2009 14:16:27 +0000 (15:16 +0100)]
move plugin directory to fit new 0.25 style

16 years agoswitch to new lsb way
mh [Fri, 30 Oct 2009 21:07:23 +0000 (22:07 +0100)]
switch to new lsb way

16 years agobetter set the variables in the init
mh [Tue, 29 Sep 2009 21:43:42 +0000 (23:43 +0200)]
better set the variables in the init

16 years agoupstream capability, fix new lines
mh [Thu, 17 Sep 2009 08:55:30 +0000 (10:55 +0200)]
upstream capability, fix new lines

- added new upstream options
- don't put new lines for control statements

16 years agofactor everything into its own file
mh [Tue, 29 Sep 2009 17:53:04 +0000 (19:53 +0200)]
factor everything into its own file

16 years agodisable gssapi
mh [Fri, 3 Apr 2009 18:19:28 +0000 (18:19 +0000)]
disable gssapi

16 years agodo not quote default!
mh [Sat, 21 Feb 2009 18:04:52 +0000 (18:04 +0000)]
do not quote default!

16 years agotry if setting a target fixes the problem
mh [Sat, 21 Feb 2009 16:36:36 +0000 (16:36 +0000)]
try if setting a target fixes the problem

16 years agochanged target behaviour
mh [Sat, 21 Feb 2009 16:24:23 +0000 (16:24 +0000)]
changed target behaviour

16 years agoadjusted to new usage of booleans
mh [Tue, 9 Dec 2008 23:05:26 +0000 (23:05 +0000)]
adjusted to new usage of booleans

16 years agoadjusted to new usage of booleans
mh [Tue, 9 Dec 2008 23:02:27 +0000 (23:02 +0000)]
adjusted to new usage of booleans

16 years agoRevert "fix missing curly brace" -- this was actually correct
Micah Anderson [Thu, 1 Oct 2009 22:30:02 +0000 (18:30 -0400)]
Revert "fix missing curly brace" -- this was actually correct

This reverts commit d4fba70a51eeb253b0155f378ce7735df9479cd4.

16 years agofix missing curly brace
Micah Anderson [Tue, 29 Sep 2009 19:32:36 +0000 (15:32 -0400)]
fix missing curly brace

16 years agofix previous change which took the client/server packages out of the linux class
Micah Anderson [Thu, 9 Jul 2009 16:15:10 +0000 (12:15 -0400)]
fix previous change which took the client/server packages out of the linux class
and instead allow for a version change through an if variable. thanks ng!

16 years agosame problem with the openssh-clients in the sshd::client::linux class
Micah Anderson [Wed, 8 Jul 2009 01:04:23 +0000 (21:04 -0400)]
same problem with the openssh-clients in the sshd::client::linux class

16 years agothe sshd::linux class cannot also define the openssh package
Micah Anderson [Wed, 8 Jul 2009 01:02:31 +0000 (21:02 -0400)]
the sshd::linux class cannot also define the openssh package
if we are to have the possibility of potentially overriding the version number it must be done in the base class

16 years agoTemplate out the possibility of specifying the key word 'off' to the
Micah Anderson [Wed, 8 Jul 2009 00:55:13 +0000 (20:55 -0400)]
Template out the possibility of specifying the key word 'off' to the
$sshd_port parameter, which simply puts a comment in front of that
option, rather than specifying it.

16 years agomake it possible to override what version of openssh-server and client are installed...
Micah Anderson [Wed, 8 Jul 2009 00:55:01 +0000 (20:55 -0400)]
make it possible to override what version of openssh-server and client are installed by providing the variable $sshd_ensure_version, which defaults to the previous value of present when not specified

16 years agoreplace the sshd_additional_options variable with two, one called
Micah Anderson [Wed, 8 Jul 2009 00:52:40 +0000 (20:52 -0400)]
replace the sshd_additional_options variable with two, one called
sshd_head_additional_options and one called sshd_tail_additional_options.
the first puts the value at the beginning of the file, and the second at
the end.

This is necessary due to some option ordering requiring things to be
before others

16 years agoremoved the facter/sshkeys.rb, this is handled by facter now days, so it is no longer...
Micah Anderson [Thu, 2 Jul 2009 16:59:16 +0000 (12:59 -0400)]
removed the facter/sshkeys.rb, this is handled by facter now days, so it is no longer necessary to provide it

17 years agoMerge commit 'anarcat/master'
Micah Anderson [Sun, 7 Dec 2008 17:17:12 +0000 (12:17 -0500)]
Merge commit 'anarcat/master'

17 years agoFix location of default sftp-server on Debian, and uncomment the sftp
Micah Anderson [Sun, 7 Dec 2008 17:15:41 +0000 (12:15 -0500)]
Fix location of default sftp-server on Debian, and uncomment the sftp
configuration line to get the sshd_config file defaults to be more
like the standard shipped defaults from Debian

17 years agoMerge commit 'ng/master'
Micah Anderson [Sun, 7 Dec 2008 17:12:33 +0000 (12:12 -0500)]
Merge commit 'ng/master'

Conflicts:

manifests/init.pp

Conflict due to indentation formatting differences

17 years agoemit a warning instead of info when the ssh server doesn't have an sshrsa key
Antoine Beaupre [Sun, 7 Dec 2008 00:12:17 +0000 (19:12 -0500)]
emit a warning instead of info when the ssh server doesn't have an sshrsa key
also export the key based on ip address, removing all warnings

17 years agouse the proper fact to export ssh keys. See http://projects.reductivelabs.com/issues...
Antoine Beaupre [Sat, 6 Dec 2008 23:39:53 +0000 (18:39 -0500)]
use the proper fact to export ssh keys. See http://projects.reductivelabs.com/issues/show/1799#note-1

17 years agomake saner defaults for authorized_keys
Antoine Beaupre [Tue, 2 Dec 2008 21:56:19 +0000 (16:56 -0500)]
make saner defaults for authorized_keys

note that this removes the user => root default

17 years agounified naming
mh [Fri, 7 Nov 2008 20:40:24 +0000 (20:40 +0000)]
unified naming

git-svn-id: https://svn/ipuppet/trunk/modules/sshd@2674 d66ca3ae-40d7-4aa7-90d4-87d79ca94279

17 years agocheck ssh with nagios
mh [Fri, 7 Nov 2008 20:19:31 +0000 (20:19 +0000)]
check ssh with nagios

git-svn-id: https://svn/ipuppet/trunk/modules/sshd@2672 d66ca3ae-40d7-4aa7-90d4-87d79ca94279

17 years agoIn debian, the daemon is run as 'sshd', but the initscript is
Micah Anderson [Mon, 27 Oct 2008 21:00:39 +0000 (17:00 -0400)]
In debian, the daemon is run as 'sshd', but the initscript is
/etc/init.d/ssh, which means that name needs to be set to 'ssh', and
pattern needs to be set to 'sshd', and then we set the hassstatus and
hasrestart depending on the lsbdistcodename

17 years agolsbdistcodename is the proper variable to check for if the system is debian or lenny
Micah Anderson [Mon, 27 Oct 2008 20:20:26 +0000 (16:20 -0400)]
lsbdistcodename is the proper variable to check for if the system is debian or lenny

17 years agoDebian's sshd config typically has PrintMotd no set because its already printed via...
Micah Anderson [Mon, 27 Oct 2008 19:45:11 +0000 (15:45 -0400)]
Debian's sshd config typically has PrintMotd no set because its already printed via PAM.
Without it set, it is defaulted to 'yes', which results in the MOTD being printed twice, so
we return the Debian default configuration in this commit

17 years agochange the debian 'hasrestart' option to a selector based on which $debian_version...
Micah Anderson [Sun, 26 Oct 2008 16:39:45 +0000 (12:39 -0400)]
change the debian 'hasrestart' option to a selector based on which $debian_version is detected,
etch does not have a ssh restart option in the initscript, but lenny does

17 years agoupdate formatting to be consistent with upstream puppet emacs mode, if this is differ...
Micah Anderson [Thu, 23 Oct 2008 19:04:47 +0000 (15:04 -0400)]
update formatting to be consistent with upstream puppet emacs mode, if this is different from the vim
mode, then there is a difference between these two editor's formatting that needs to be resolved

17 years agoMerge branch 'master' of gitosis@labs.riseup.net:module_sshd
Micah Anderson [Thu, 23 Oct 2008 19:01:53 +0000 (15:01 -0400)]
Merge branch 'master' of gitosis@labs.riseup.net:module_sshd

17 years agodebian has both status and restart options, in fact restart is
Micah Anderson [Thu, 23 Oct 2008 18:59:42 +0000 (14:59 -0400)]
debian has both status and restart options, in fact restart is
preferable because a stop/start operation can leave sshd broken
because the stop wont stop before the start is run. On the next puppet
run ssh will be brought back up, but its a hair-raising few minutes
while you wonder what happened

17 years agoMerge commit 'immerda/master'
Pietro Ferrari [Tue, 21 Oct 2008 00:03:37 +0000 (02:03 +0200)]
Merge commit 'immerda/master'

17 years agonew options, cleaned up real_ hack
mh [Mon, 20 Oct 2008 22:46:50 +0000 (22:46 +0000)]
new options, cleaned up real_ hack

git-svn-id: https://svn/ipuppet/trunk/modules/sshd@2527 d66ca3ae-40d7-4aa7-90d4-87d79ca94279

17 years agoremove deprecated define
mh [Thu, 2 Oct 2008 22:04:31 +0000 (22:04 +0000)]
remove deprecated define

git-svn-id: https://svn/ipuppet/trunk/modules/sshd@2317 d66ca3ae-40d7-4aa7-90d4-87d79ca94279

17 years agoMerge commit 'ng/master'
Micah Anderson [Wed, 1 Oct 2008 01:04:46 +0000 (21:04 -0400)]
Merge commit 'ng/master'

17 years agofix correct inheritance
mh [Tue, 30 Sep 2008 20:13:47 +0000 (20:13 +0000)]
fix correct inheritance

git-svn-id: https://svn/ipuppet/trunk/modules/sshd@2272 d66ca3ae-40d7-4aa7-90d4-87d79ca94279

17 years agoremove dependency completly
mh [Mon, 29 Sep 2008 22:50:28 +0000 (22:50 +0000)]
remove dependency completly

git-svn-id: https://svn/ipuppet/trunk/modules/sshd@2267 d66ca3ae-40d7-4aa7-90d4-87d79ca94279

17 years agomoved package depency to the linux class, openbsd doesn't have this package
mh [Mon, 29 Sep 2008 22:48:35 +0000 (22:48 +0000)]
moved package depency to the linux class, openbsd doesn't have this package

git-svn-id: https://svn/ipuppet/trunk/modules/sshd@2266 d66ca3ae-40d7-4aa7-90d4-87d79ca94279

17 years agofactored out the package to some subclasses as openbsd doesn't need such a package
mh [Mon, 29 Sep 2008 22:45:39 +0000 (22:45 +0000)]
factored out the package to some subclasses as openbsd doesn't need such a package

git-svn-id: https://svn/ipuppet/trunk/modules/sshd@2265 d66ca3ae-40d7-4aa7-90d4-87d79ca94279

17 years agoadded link for lsb stuff
mh [Mon, 29 Sep 2008 22:41:25 +0000 (22:41 +0000)]
added link for lsb stuff

git-svn-id: https://svn/ipuppet/trunk/modules/sshd@2264 d66ca3ae-40d7-4aa7-90d4-87d79ca94279

17 years agomerged with riseup
mh [Mon, 29 Sep 2008 22:37:26 +0000 (22:37 +0000)]
merged with riseup

git-svn-id: https://svn/ipuppet/trunk/modules/sshd@2263 d66ca3ae-40d7-4aa7-90d4-87d79ca94279

17 years agoinclude assert_lsbdistcodename for debian
Micah Anderson [Sun, 28 Sep 2008 17:40:35 +0000 (13:40 -0400)]
include assert_lsbdistcodename for debian

17 years agoadd some comments to clarify how to set variables, and provide examples
Micah Anderson [Sun, 28 Sep 2008 16:38:18 +0000 (12:38 -0400)]
add some comments to clarify how to set variables, and provide examples

17 years agoclarify in the example about how you can set multiple ListenAddresses with the right...
Micah Anderson [Sat, 27 Sep 2008 21:45:57 +0000 (17:45 -0400)]
clarify in the example about how you can set multiple ListenAddresses with the right syntax
also set the default to be 0.0.0.0 and :: which is the normal default for all IPv4 and all IPv6 addresses

17 years agorename the templates to coincide with the downcased lsbdistcodename
Micah Anderson [Sat, 27 Sep 2008 20:51:32 +0000 (16:51 -0400)]
rename the templates to coincide with the downcased lsbdistcodename
also add a missing comma in the content selector

17 years agoChange the template naming:
Micah Anderson [Sat, 27 Sep 2008 20:42:08 +0000 (16:42 -0400)]
Change the template naming:
1. remove the _normal suffix, as it is not used
2. add a selector to look for the variable $lsbdistcodename being set and use that in selecting a template
this is useful to create a Debian_Etch.erb and a Debian_Lenny.erb which can have different values. For example
the Debian Etch version of openssh does not have the AllowAgentForwarding option, and if it is included, ssh will
fail to start

17 years agoremove some newlines from the template to clean it up a bit
Micah Anderson [Sat, 27 Sep 2008 19:32:12 +0000 (15:32 -0400)]
remove some newlines from the template to clean it up a bit

17 years agofix the default of PubkeyAuthentication (supposed to be yes, but was set to no)
Micah Anderson [Sat, 27 Sep 2008 19:19:43 +0000 (15:19 -0400)]
fix the default of PubkeyAuthentication (supposed to be yes, but was set to no)

17 years agofix duplicate sshd word in variable name
Micah Anderson [Sat, 27 Sep 2008 17:39:28 +0000 (13:39 -0400)]
fix duplicate sshd word in variable name

17 years agoadd the ability to set the ListenAddress configuration option through sshd_listen_address
Micah Anderson [Sat, 27 Sep 2008 17:30:52 +0000 (13:30 -0400)]
add the ability to set the ListenAddress configuration option through sshd_listen_address

17 years agoadjust template to not leave behind so many empty lines
Micah Anderson [Sat, 27 Sep 2008 17:20:32 +0000 (13:20 -0400)]
adjust template to not leave behind so many empty lines

17 years agofix minor spelling error
Micah Anderson [Sat, 27 Sep 2008 16:17:12 +0000 (12:17 -0400)]
fix minor spelling error

17 years agofix incorrect variable sshd_permit_empty_passwords
Micah Anderson [Sat, 27 Sep 2008 15:51:58 +0000 (11:51 -0400)]
fix incorrect variable sshd_permit_empty_passwords

17 years agoadd the variable sshd_authorized_keys_file with the default set to the normal: %h...
Micah Anderson [Sat, 27 Sep 2008 00:03:10 +0000 (20:03 -0400)]
add the variable sshd_authorized_keys_file with the default set to the normal: %h/.ssh/authorized_keys

17 years agoadd sshd_port variable enabling you to set a different port for sshd, default is 22
Micah Anderson [Fri, 26 Sep 2008 22:23:25 +0000 (18:23 -0400)]
add sshd_port variable enabling you to set a different port for sshd, default is 22

17 years agominor fix to indentation
Micah Anderson [Fri, 26 Sep 2008 22:16:58 +0000 (18:16 -0400)]
minor fix to indentation

17 years agoadd sshd_allow_tcp_forwarding variable, with the default changed to no (note this...
Micah Anderson [Fri, 26 Sep 2008 21:55:02 +0000 (17:55 -0400)]
add sshd_allow_tcp_forwarding variable, with the default changed to no (note this is opposite of
what the existing template had enabled for Debian, but this is a better setting)

17 years agoadd variable sshd_permit_empty_passwords, with the default set to no
Micah Anderson [Fri, 26 Sep 2008 21:51:12 +0000 (17:51 -0400)]
add variable sshd_permit_empty_passwords, with the default set to no

17 years agofix ignore_rhosts variable name
Micah Anderson [Fri, 26 Sep 2008 21:46:36 +0000 (17:46 -0400)]
fix ignore_rhosts variable name

17 years agoadded sshd_rhosts_rsa_authentication variable, default set to no
Micah Anderson [Fri, 26 Sep 2008 21:34:09 +0000 (17:34 -0400)]
added sshd_rhosts_rsa_authentication variable, default set to no
added sshd_hostbased_authentication variable, default set to no

17 years agoadd sshd_ignore_rhosts option, default set to yes
Micah Anderson [Fri, 26 Sep 2008 21:30:28 +0000 (17:30 -0400)]
add sshd_ignore_rhosts option, default set to yes

17 years agoadd the sshd_strict_modes variable, with the default set to yes
Micah Anderson [Fri, 26 Sep 2008 21:28:05 +0000 (17:28 -0400)]
add the sshd_strict_modes variable, with the default set to yes

17 years agofix a set of duplicated sshd words in the variables
Micah Anderson [Fri, 26 Sep 2008 21:23:39 +0000 (17:23 -0400)]
fix a set of duplicated sshd words in the variables

17 years agoadd the sshd_rsa_authentication option, default set to no
Micah Anderson [Fri, 26 Sep 2008 21:21:01 +0000 (17:21 -0400)]
add the sshd_rsa_authentication option, default set to no

17 years agoadd sshd_pubkey_authentication variable, with the default set to yes
Micah Anderson [Fri, 26 Sep 2008 21:10:33 +0000 (17:10 -0400)]
add sshd_pubkey_authentication variable, with the default set to yes

17 years agoadded sshd_challenge_response_authentication variable, with the default value set...
Micah Anderson [Fri, 26 Sep 2008 21:05:49 +0000 (17:05 -0400)]
added sshd_challenge_response_authentication variable, with the default value set to no

17 years agoadd comment about PAM auth to the Debian template (copied from the Gentoo one), as...
Micah Anderson [Fri, 26 Sep 2008 20:59:55 +0000 (16:59 -0400)]
add comment about PAM auth to the Debian template (copied from the Gentoo one), as its useful info to
have available, due to the complexity of the option

17 years agoAdd the variable AllowAgentForwarding to be set, with the default of 'no', only the...
Micah Anderson [Fri, 26 Sep 2008 20:57:59 +0000 (16:57 -0400)]
Add the variable AllowAgentForwarding to be set, with the default of 'no', only the Debian
template was adjusted for this, as my knowledge of the other operating systems is not good enough
to determine the appropriate setting there