Compare commits
1 Commits
6156b81469
...
bdee6e9aaa
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bdee6e9aaa |
@@ -131,21 +131,7 @@
|
|||||||
33
|
33
|
||||||
34
|
34
|
||||||
35
|
35
|
||||||
36
|
36</pre>
|
||||||
37
|
|
||||||
38
|
|
||||||
39
|
|
||||||
40
|
|
||||||
41
|
|
||||||
42
|
|
||||||
43
|
|
||||||
44
|
|
||||||
45
|
|
||||||
46
|
|
||||||
47
|
|
||||||
48
|
|
||||||
49
|
|
||||||
50</pre>
|
|
||||||
</td>
|
</td>
|
||||||
<td>
|
<td>
|
||||||
<pre class="code"><span class="info file"># File 'manifests/main/dirs.pp', line 6</span>
|
<pre class="code"><span class="info file"># File 'manifests/main/dirs.pp', line 6</span>
|
||||||
@@ -180,20 +166,6 @@ class confdroid_nrpe::main::dirs (
|
|||||||
seltype => var_run_t,
|
seltype => var_run_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
}
|
}
|
||||||
|
|
||||||
if $ne_enable_ssl {
|
|
||||||
file { $ne_servercert_dir:
|
|
||||||
ensure => directory,
|
|
||||||
path => $ne_servercert_dir,
|
|
||||||
owner => 'root',
|
|
||||||
group => 'root',
|
|
||||||
mode => '0755',
|
|
||||||
selrange => s0,
|
|
||||||
selrole => object_r,
|
|
||||||
seltype => cert_t,
|
|
||||||
seluser => system_u,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}</pre>
|
}</pre>
|
||||||
</td>
|
</td>
|
||||||
</tr>
|
</tr>
|
||||||
|
|||||||
@@ -367,6 +367,24 @@ inherited by all classes except defines.
|
|||||||
|
|
||||||
</li>
|
</li>
|
||||||
|
|
||||||
|
<li>
|
||||||
|
|
||||||
|
<span class='name'>ne_ssl_use_adh</span>
|
||||||
|
|
||||||
|
|
||||||
|
<span class='type'>(<tt>String</tt>)</span>
|
||||||
|
|
||||||
|
|
||||||
|
<em class="default">(defaults to: <tt>'1'</tt>)</em>
|
||||||
|
|
||||||
|
|
||||||
|
—
|
||||||
|
<div class='inline'>
|
||||||
|
<p>This is for backward compatibility and is DEPRECATED. Set to 1 to enable ADH or 2 to require ADH. 1 is currently the default but will be changed in a later version.</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</li>
|
||||||
|
|
||||||
<li>
|
<li>
|
||||||
|
|
||||||
<span class='name'>ne_ssl_cipher_list</span>
|
<span class='name'>ne_ssl_cipher_list</span>
|
||||||
@@ -393,7 +411,7 @@ inherited by all classes except defines.
|
|||||||
<span class='type'>(<tt>String</tt>)</span>
|
<span class='type'>(<tt>String</tt>)</span>
|
||||||
|
|
||||||
|
|
||||||
<em class="default">(defaults to: <tt>'0'</tt>)</em>
|
<em class="default">(defaults to: <tt>'2'</tt>)</em>
|
||||||
|
|
||||||
|
|
||||||
—
|
—
|
||||||
@@ -781,9 +799,6 @@ inherited by all classes except defines.
|
|||||||
<pre class="lines">
|
<pre class="lines">
|
||||||
|
|
||||||
|
|
||||||
84
|
|
||||||
85
|
|
||||||
86
|
|
||||||
87
|
87
|
||||||
88
|
88
|
||||||
89
|
89
|
||||||
@@ -874,10 +889,13 @@ inherited by all classes except defines.
|
|||||||
174
|
174
|
||||||
175
|
175
|
||||||
176
|
176
|
||||||
177</pre>
|
177
|
||||||
|
178
|
||||||
|
179
|
||||||
|
180</pre>
|
||||||
</td>
|
</td>
|
||||||
<td>
|
<td>
|
||||||
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 84</span>
|
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 87</span>
|
||||||
|
|
||||||
class confdroid_nrpe::params (
|
class confdroid_nrpe::params (
|
||||||
|
|
||||||
@@ -910,8 +928,9 @@ class confdroid_nrpe::params (
|
|||||||
String $ne_allow_weak_rnd_seed = '1',
|
String $ne_allow_weak_rnd_seed = '1',
|
||||||
Boolean $ne_enable_ssl = false,
|
Boolean $ne_enable_ssl = false,
|
||||||
String $ne_ssl_version = 'TLSv2+',
|
String $ne_ssl_version = 'TLSv2+',
|
||||||
|
String $ne_ssl_use_adh = '1',
|
||||||
String $ne_ssl_cipher_list = 'ALL:!aNULL:!eNULL:!SSLv2:!LOW:!EXP:!RC4:!MD5:@STRENGTH',
|
String $ne_ssl_cipher_list = 'ALL:!aNULL:!eNULL:!SSLv2:!LOW:!EXP:!RC4:!MD5:@STRENGTH',
|
||||||
String $ne_ssl_client_certs = '0',
|
String $ne_ssl_client_certs = '2',
|
||||||
String $ne_ssl_logging = '0x00',
|
String $ne_ssl_logging = '0x00',
|
||||||
Array $ne_nasty_metachars = ["|`&><'\\[]{};\r\n"],
|
Array $ne_nasty_metachars = ["|`&><'\\[]{};\r\n"],
|
||||||
String $ne_include_file = '',
|
String $ne_include_file = '',
|
||||||
@@ -944,7 +963,6 @@ class confdroid_nrpe::params (
|
|||||||
# directories
|
# directories
|
||||||
$ne_main_conf_d_dir = '/etc/nrpe.d'
|
$ne_main_conf_d_dir = '/etc/nrpe.d'
|
||||||
$ne_run_dir = '/var/run/nrpe'
|
$ne_run_dir = '/var/run/nrpe'
|
||||||
$ne_servercert_dir = '/etc/pki/tls/servercerts'
|
|
||||||
|
|
||||||
# files
|
# files
|
||||||
$ne_main_conf_file = '/etc/nagios/nrpe.cfg'
|
$ne_main_conf_file = '/etc/nagios/nrpe.cfg'
|
||||||
@@ -963,11 +981,11 @@ class confdroid_nrpe::params (
|
|||||||
$ne_checkmodule_nrpe_erb = 'confdroid_nrpe/checkmodule_nrpe.erb'
|
$ne_checkmodule_nrpe_erb = 'confdroid_nrpe/checkmodule_nrpe.erb'
|
||||||
$ne_nrpe_pp_file = "${ne_main_conf_d_dir}/nrpe.pp"
|
$ne_nrpe_pp_file = "${ne_main_conf_d_dir}/nrpe.pp"
|
||||||
$ne_semodule_erb = 'confdroid_nrpe/semodule_nrpe.erb'
|
$ne_semodule_erb = 'confdroid_nrpe/semodule_nrpe.erb'
|
||||||
$ne_ssl_cert_file = "${ne_servercert_dir}/nagios-crt.pem"
|
$ne_ssl_cert_file = '/etc/pki/tls/certs/nagios.crt.pem'
|
||||||
$ne_ssl_cert_erb = 'confdroid_nrpe/ssl_cert.erb'
|
$ne_ssl_cert_erb = 'confdroid_nrpe/ssl_cert.erb'
|
||||||
$ne_ssl_privatekey_file = "${ne_servercert_dir}/nagios-key.pem"
|
$ne_ssl_privatekey_file = '/etc/pki/tls/private/nagios.key.pem'
|
||||||
$ne_ssl_privatekey_erb = 'confdroid_nrpe/ssl_privatekey.erb'
|
$ne_ssl_privatekey_erb = 'confdroid_nrpe/ssl_privatekey.erb'
|
||||||
$ne_ssl_ca_cert_file = "${ne_servercert_dir}/ca-cert.pem"
|
$ne_ssl_ca_cert_file = '/etc/pki/tls/certs/ca-chain.crt.pem'
|
||||||
$ne_ssl_ca_cert_erb = 'confdroid_nrpe/ssl_ca_cert.erb'
|
$ne_ssl_ca_cert_erb = 'confdroid_nrpe/ssl_ca_cert.erb'
|
||||||
|
|
||||||
# includes must be last
|
# includes must be last
|
||||||
|
|||||||
@@ -33,18 +33,4 @@ class confdroid_nrpe::main::dirs (
|
|||||||
seltype => var_run_t,
|
seltype => var_run_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
}
|
}
|
||||||
|
|
||||||
if $ne_enable_ssl {
|
|
||||||
file { $ne_servercert_dir:
|
|
||||||
ensure => directory,
|
|
||||||
path => $ne_servercert_dir,
|
|
||||||
owner => 'root',
|
|
||||||
group => 'root',
|
|
||||||
mode => '0755',
|
|
||||||
selrange => s0,
|
|
||||||
selrole => object_r,
|
|
||||||
seltype => cert_t,
|
|
||||||
seluser => system_u,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -32,6 +32,9 @@
|
|||||||
# NRPE daemon will wait for a connection to be established before exiting.
|
# NRPE daemon will wait for a connection to be established before exiting.
|
||||||
# @param [String] ne_ssl_version These directives allow you to specify how to
|
# @param [String] ne_ssl_version These directives allow you to specify how to
|
||||||
# use SSL/TLS.
|
# use SSL/TLS.
|
||||||
|
# @param [String] ne_ssl_use_adh This is for backward compatibility and is
|
||||||
|
# DEPRECATED. Set to 1 to enable ADH or 2 to require ADH. 1 is currently the
|
||||||
|
# default but will be changed in a later version.
|
||||||
# @param [String] ne_ssl_cipher_list ciphers can be used. For backward
|
# @param [String] ne_ssl_cipher_list ciphers can be used. For backward
|
||||||
# compatibility, this defaults to 'ssl_cipher_list=ALL:!MD5:@STRENGTH' in
|
# compatibility, this defaults to 'ssl_cipher_list=ALL:!MD5:@STRENGTH' in
|
||||||
# this version but will be changed in a later version of NRPE.
|
# this version but will be changed in a later version of NRPE.
|
||||||
@@ -112,8 +115,9 @@ class confdroid_nrpe::params (
|
|||||||
String $ne_allow_weak_rnd_seed = '1',
|
String $ne_allow_weak_rnd_seed = '1',
|
||||||
Boolean $ne_enable_ssl = false,
|
Boolean $ne_enable_ssl = false,
|
||||||
String $ne_ssl_version = 'TLSv2+',
|
String $ne_ssl_version = 'TLSv2+',
|
||||||
|
String $ne_ssl_use_adh = '1',
|
||||||
String $ne_ssl_cipher_list = 'ALL:!aNULL:!eNULL:!SSLv2:!LOW:!EXP:!RC4:!MD5:@STRENGTH',
|
String $ne_ssl_cipher_list = 'ALL:!aNULL:!eNULL:!SSLv2:!LOW:!EXP:!RC4:!MD5:@STRENGTH',
|
||||||
String $ne_ssl_client_certs = '0',
|
String $ne_ssl_client_certs = '2',
|
||||||
String $ne_ssl_logging = '0x00',
|
String $ne_ssl_logging = '0x00',
|
||||||
Array $ne_nasty_metachars = ["|`&><'\\[]{};\r\n"],
|
Array $ne_nasty_metachars = ["|`&><'\\[]{};\r\n"],
|
||||||
String $ne_include_file = '',
|
String $ne_include_file = '',
|
||||||
@@ -146,7 +150,6 @@ class confdroid_nrpe::params (
|
|||||||
# directories
|
# directories
|
||||||
$ne_main_conf_d_dir = '/etc/nrpe.d'
|
$ne_main_conf_d_dir = '/etc/nrpe.d'
|
||||||
$ne_run_dir = '/var/run/nrpe'
|
$ne_run_dir = '/var/run/nrpe'
|
||||||
$ne_servercert_dir = '/etc/pki/tls/servercerts'
|
|
||||||
|
|
||||||
# files
|
# files
|
||||||
$ne_main_conf_file = '/etc/nagios/nrpe.cfg'
|
$ne_main_conf_file = '/etc/nagios/nrpe.cfg'
|
||||||
@@ -165,11 +168,11 @@ class confdroid_nrpe::params (
|
|||||||
$ne_checkmodule_nrpe_erb = 'confdroid_nrpe/checkmodule_nrpe.erb'
|
$ne_checkmodule_nrpe_erb = 'confdroid_nrpe/checkmodule_nrpe.erb'
|
||||||
$ne_nrpe_pp_file = "${ne_main_conf_d_dir}/nrpe.pp"
|
$ne_nrpe_pp_file = "${ne_main_conf_d_dir}/nrpe.pp"
|
||||||
$ne_semodule_erb = 'confdroid_nrpe/semodule_nrpe.erb'
|
$ne_semodule_erb = 'confdroid_nrpe/semodule_nrpe.erb'
|
||||||
$ne_ssl_cert_file = "${ne_servercert_dir}/nagios-crt.pem"
|
$ne_ssl_cert_file = '/etc/pki/tls/certs/nagios.crt.pem'
|
||||||
$ne_ssl_cert_erb = 'confdroid_nrpe/ssl_cert.erb'
|
$ne_ssl_cert_erb = 'confdroid_nrpe/ssl_cert.erb'
|
||||||
$ne_ssl_privatekey_file = "${ne_servercert_dir}/nagios-key.pem"
|
$ne_ssl_privatekey_file = '/etc/pki/tls/private/nagios.key.pem'
|
||||||
$ne_ssl_privatekey_erb = 'confdroid_nrpe/ssl_privatekey.erb'
|
$ne_ssl_privatekey_erb = 'confdroid_nrpe/ssl_privatekey.erb'
|
||||||
$ne_ssl_ca_cert_file = "${ne_servercert_dir}/ca-cert.pem"
|
$ne_ssl_ca_cert_file = '/etc/pki/tls/certs/ca-chain.crt.pem'
|
||||||
$ne_ssl_ca_cert_erb = 'confdroid_nrpe/ssl_ca_cert.erb'
|
$ne_ssl_ca_cert_erb = 'confdroid_nrpe/ssl_ca_cert.erb'
|
||||||
|
|
||||||
# includes must be last
|
# includes must be last
|
||||||
|
|||||||
@@ -35,6 +35,7 @@ allow_weak_random_seed=<%= @ne_allow_weak_rnd_seed %>
|
|||||||
|
|
||||||
<% if @ne_enable_ssl == true -%>
|
<% if @ne_enable_ssl == true -%>
|
||||||
ssl_version=<%= @ne_ssl_version %>
|
ssl_version=<%= @ne_ssl_version %>
|
||||||
|
ssl_use_adh=<%= @ne_ssl_use_adh %>
|
||||||
ssl_cipher_list=<%= @ne_ssl_cipher_list %>
|
ssl_cipher_list=<%= @ne_ssl_cipher_list %>
|
||||||
ssl_cacert_file=<%= @ne_ssl_ca_cert_file %>
|
ssl_cacert_file=<%= @ne_ssl_ca_cert_file %>
|
||||||
ssl_cert_file=<%= @ne_ssl_cert_file %>
|
ssl_cert_file=<%= @ne_ssl_cert_file %>
|
||||||
|
|||||||
Reference in New Issue
Block a user