diff --git a/README.md b/README.md index 284dbf4..db98e76 100644 --- a/README.md +++ b/README.md @@ -102,13 +102,13 @@ It is very recommendable to define such commands directly within Puppet modules ## managing TLS certificates -When `ne_enable_ssl` is enabled (default), the certificates for the ca (root if standalone or intermediate), the nagios server and the key for the nagios server have to be provided through the following values: +When `ne_enable_ssl` is enabled, the certificates for the ca (root if standalone or intermediate), the nagios server and the key for the nagios server have to be provided through the following values: - `ne_ssl_ca_cert_pem` - `ne_ssl_cert_pem` - `ne_ssl_privatekey_pem` -via Hiera (if you use it) or ENC. +via Hiera (if you use it) or ENC. At the ENC need to add confdroid_nrpe::params and set those values. ## SELINUX diff --git a/manifests/params.pp b/manifests/params.pp index 74e2a64..218ace6 100644 --- a/manifests/params.pp +++ b/manifests/params.pp @@ -115,7 +115,7 @@ class confdroid_nrpe::params ( String $ne_command_timeout = '60', String $ne_connection_timeout = '300', String $ne_allow_weak_rnd_seed = '1', - Boolean $ne_enable_ssl = true, + Boolean $ne_enable_ssl = false, String $ne_ssl_version = 'TLSv2+', String $ne_ssl_use_adh = '1', String $ne_ssl_cipher_list = 'ALL:!aNULL:!eNULL:!SSLv2:!LOW:!EXP:!RC4:!MD5:@STRENGTH',