Compare commits
1 Commits
master
...
dcdbccc3cb
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
dcdbccc3cb |
12
README.md
12
README.md
@@ -102,22 +102,14 @@ It is very recommendable to define such commands directly within Puppet modules
|
|||||||
|
|
||||||
## managing TLS certificates
|
## managing TLS certificates
|
||||||
|
|
||||||
When `ne_enable_ssl` is enabled, the certificates for the ca (root if standalone or intermediate), the nagios server and the key for the nagios server have to be provided through the following values:
|
|
||||||
|
|
||||||
- `ne_ssl_ca_cert_pem`
|
|
||||||
- `ne_ssl_cert_pem`
|
|
||||||
- `ne_ssl_privatekey_pem`
|
|
||||||
|
|
||||||
via Hiera (if you use it) or ENC. At the ENC need to add confdroid_nrpe::params and set those values.
|
|
||||||
|
|
||||||
If you don't need TLS encryption, leave `ne_enable_ssl` to the default value of `false`.
|
|
||||||
|
|
||||||
## SELINUX
|
## SELINUX
|
||||||
|
|
||||||
All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.
|
All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.
|
||||||
|
|
||||||
## Known Problems
|
## Known Problems
|
||||||
|
|
||||||
|
- SSL/TLS support: Version 3 of NRPE supposedly has support for SSL/ TLs. However, at the time of writing this module, this seems to be buggy, as I was unable to start the NRPE service as soon as the `ssl_cert_file` line was uncommented in the configuration file, despite having valid certs in the right position on the node. This happened when installing manually, not through this Puppet module. For that reason I included the `$ne_enable_ssl` boolean parameter, which is set to `false` by default, hence disabling SSL/TLS options until this has been fixed upstream, or a valid workaround has been found. Setting this option to `true` will include all SSL / TLS settings.
|
||||||
|
|
||||||
## Troubleshooting
|
## Troubleshooting
|
||||||
|
|
||||||
- `CHECK_NRPE: Unable to read output`: Nagios sudo access also needs Selinux to allow this. Default settings in this module take care for both through `$ne_allow_sudo` and `$ne_include_selinux`.
|
- `CHECK_NRPE: Unable to read output`: Nagios sudo access also needs Selinux to allow this. Default settings in this module take care for both through `$ne_allow_sudo` and `$ne_include_selinux`.
|
||||||
|
|||||||
@@ -193,24 +193,14 @@
|
|||||||
|
|
||||||
<h2 id="label-managing+TLS+certificates">managing TLS certificates</h2>
|
<h2 id="label-managing+TLS+certificates">managing TLS certificates</h2>
|
||||||
|
|
||||||
<p>When <code>ne_enable_ssl</code> is enabled, the certificates for the ca (root if standalone or intermediate), the nagios server and the key for the nagios server have to be provided through the following values:</p>
|
|
||||||
<ul><li>
|
|
||||||
<p><code>ne_ssl_ca_cert_pem</code></p>
|
|
||||||
</li><li>
|
|
||||||
<p><code>ne_ssl_cert_pem</code></p>
|
|
||||||
</li><li>
|
|
||||||
<p><code>ne_ssl_privatekey_pem</code></p>
|
|
||||||
</li></ul>
|
|
||||||
|
|
||||||
<p>via Hiera (if you use it) or ENC. At the ENC need to add confdroid_nrpe::params and set those values.</p>
|
|
||||||
|
|
||||||
<p>If you don’t need TLS encryption, leave <code>ne_enable_ssl</code> to the default value of <code>false</code>.</p>
|
|
||||||
|
|
||||||
<h2 id="label-SELINUX">SELINUX</h2>
|
<h2 id="label-SELINUX">SELINUX</h2>
|
||||||
|
|
||||||
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.</p>
|
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.</p>
|
||||||
|
|
||||||
<h2 id="label-Known+Problems">Known Problems</h2>
|
<h2 id="label-Known+Problems">Known Problems</h2>
|
||||||
|
<ul><li>
|
||||||
|
<p>SSL/TLS support: Version 3 of NRPE supposedly has support for SSL/ TLs. However, at the time of writing this module, this seems to be buggy, as I was unable to start the NRPE service as soon as the <code>ssl_cert_file</code> line was uncommented in the configuration file, despite having valid certs in the right position on the node. This happened when installing manually, not through this Puppet module. For that reason I included the <code>$ne_enable_ssl</code> boolean parameter, which is set to <code>false</code> by default, hence disabling SSL/TLS options until this has been fixed upstream, or a valid workaround has been found. Setting this option to <code>true</code> will include all SSL / TLS settings.</p>
|
||||||
|
</li></ul>
|
||||||
|
|
||||||
<h2 id="label-Troubleshooting">Troubleshooting</h2>
|
<h2 id="label-Troubleshooting">Troubleshooting</h2>
|
||||||
<ul><li>
|
<ul><li>
|
||||||
|
|||||||
@@ -193,24 +193,14 @@
|
|||||||
|
|
||||||
<h2 id="label-managing+TLS+certificates">managing TLS certificates</h2>
|
<h2 id="label-managing+TLS+certificates">managing TLS certificates</h2>
|
||||||
|
|
||||||
<p>When <code>ne_enable_ssl</code> is enabled, the certificates for the ca (root if standalone or intermediate), the nagios server and the key for the nagios server have to be provided through the following values:</p>
|
|
||||||
<ul><li>
|
|
||||||
<p><code>ne_ssl_ca_cert_pem</code></p>
|
|
||||||
</li><li>
|
|
||||||
<p><code>ne_ssl_cert_pem</code></p>
|
|
||||||
</li><li>
|
|
||||||
<p><code>ne_ssl_privatekey_pem</code></p>
|
|
||||||
</li></ul>
|
|
||||||
|
|
||||||
<p>via Hiera (if you use it) or ENC. At the ENC need to add confdroid_nrpe::params and set those values.</p>
|
|
||||||
|
|
||||||
<p>If you don’t need TLS encryption, leave <code>ne_enable_ssl</code> to the default value of <code>false</code>.</p>
|
|
||||||
|
|
||||||
<h2 id="label-SELINUX">SELINUX</h2>
|
<h2 id="label-SELINUX">SELINUX</h2>
|
||||||
|
|
||||||
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.</p>
|
<p>All files and directories are configured with correct selinux context. If selinux is disabled, these contexts are ignored.</p>
|
||||||
|
|
||||||
<h2 id="label-Known+Problems">Known Problems</h2>
|
<h2 id="label-Known+Problems">Known Problems</h2>
|
||||||
|
<ul><li>
|
||||||
|
<p>SSL/TLS support: Version 3 of NRPE supposedly has support for SSL/ TLs. However, at the time of writing this module, this seems to be buggy, as I was unable to start the NRPE service as soon as the <code>ssl_cert_file</code> line was uncommented in the configuration file, despite having valid certs in the right position on the node. This happened when installing manually, not through this Puppet module. For that reason I included the <code>$ne_enable_ssl</code> boolean parameter, which is set to <code>false</code> by default, hence disabling SSL/TLS options until this has been fixed upstream, or a valid workaround has been found. Setting this option to <code>true</code> will include all SSL / TLS settings.</p>
|
||||||
|
</li></ul>
|
||||||
|
|
||||||
<h2 id="label-Troubleshooting">Troubleshooting</h2>
|
<h2 id="label-Troubleshooting">Troubleshooting</h2>
|
||||||
<ul><li>
|
<ul><li>
|
||||||
|
|||||||
@@ -131,21 +131,7 @@
|
|||||||
33
|
33
|
||||||
34
|
34
|
||||||
35
|
35
|
||||||
36
|
36</pre>
|
||||||
37
|
|
||||||
38
|
|
||||||
39
|
|
||||||
40
|
|
||||||
41
|
|
||||||
42
|
|
||||||
43
|
|
||||||
44
|
|
||||||
45
|
|
||||||
46
|
|
||||||
47
|
|
||||||
48
|
|
||||||
49
|
|
||||||
50</pre>
|
|
||||||
</td>
|
</td>
|
||||||
<td>
|
<td>
|
||||||
<pre class="code"><span class="info file"># File 'manifests/main/dirs.pp', line 6</span>
|
<pre class="code"><span class="info file"># File 'manifests/main/dirs.pp', line 6</span>
|
||||||
@@ -180,20 +166,6 @@ class confdroid_nrpe::main::dirs (
|
|||||||
seltype => var_run_t,
|
seltype => var_run_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
}
|
}
|
||||||
|
|
||||||
if $ne_enable_ssl {
|
|
||||||
file { $ne_servercert_dir:
|
|
||||||
ensure => directory,
|
|
||||||
path => $ne_servercert_dir,
|
|
||||||
owner => 'root',
|
|
||||||
group => 'root',
|
|
||||||
mode => '0755',
|
|
||||||
selrange => s0,
|
|
||||||
selrole => object_r,
|
|
||||||
seltype => cert_t,
|
|
||||||
seluser => system_u,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}</pre>
|
}</pre>
|
||||||
</td>
|
</td>
|
||||||
</tr>
|
</tr>
|
||||||
|
|||||||
@@ -206,7 +206,9 @@
|
|||||||
108
|
108
|
||||||
109
|
109
|
||||||
110
|
110
|
||||||
111</pre>
|
111
|
||||||
|
112
|
||||||
|
113</pre>
|
||||||
</td>
|
</td>
|
||||||
<td>
|
<td>
|
||||||
<pre class="code"><span class="info file"># File 'manifests/main/files.pp', line 6</span>
|
<pre class="code"><span class="info file"># File 'manifests/main/files.pp', line 6</span>
|
||||||
@@ -249,6 +251,7 @@ class confdroid_nrpe::main::files (
|
|||||||
}
|
}
|
||||||
|
|
||||||
if $ne_allow_sudo == true {
|
if $ne_allow_sudo == true {
|
||||||
|
|
||||||
file { $ne_sudo_file:
|
file { $ne_sudo_file:
|
||||||
ensure => file,
|
ensure => file,
|
||||||
path => $ne_sudo_file,
|
path => $ne_sudo_file,
|
||||||
@@ -276,44 +279,45 @@ class confdroid_nrpe::main::files (
|
|||||||
content => template($ne_nrpe_te_erb),
|
content => template($ne_nrpe_te_erb),
|
||||||
notify => Exec['create_nrpe_pp'],
|
notify => Exec['create_nrpe_pp'],
|
||||||
}
|
}
|
||||||
}
|
|
||||||
# file for ssl certificate
|
# file for ssl certificate
|
||||||
if $ne_enable_ssl == true {
|
if $ne_enable_ssl == true {
|
||||||
file { $ne_ssl_cert_file:
|
file { $ne_ssl_cert_file:
|
||||||
ensure => file,
|
ensure => file,
|
||||||
path => $ne_ssl_cert_file,
|
path => $ne_ssl_cert_file,
|
||||||
owner => $ne_user,
|
owner => 'root',
|
||||||
group => $ne_user,
|
group => 'root',
|
||||||
mode => '0440',
|
mode => '0644',
|
||||||
selrange => s0,
|
selrange => s0,
|
||||||
selrole => object_r,
|
selrole => object_r,
|
||||||
seltype => cert_t,
|
seltype => cert_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
content => template($ne_ssl_cert_erb),
|
content => template($ne_ssl_cert_erb),
|
||||||
}
|
}
|
||||||
file { $ne_ssl_privatekey_file:
|
file { $ne_ssl_privatekey_file:
|
||||||
ensure => file,
|
ensure => file,
|
||||||
path => $ne_ssl_privatekey_file,
|
path => $ne_ssl_privatekey_file,
|
||||||
owner => $ne_user,
|
owner => 'root',
|
||||||
group => $ne_user,
|
group => 'root',
|
||||||
mode => '0400',
|
mode => '0600',
|
||||||
selrange => s0,
|
selrange => s0,
|
||||||
selrole => object_r,
|
selrole => object_r,
|
||||||
seltype => cert_t,
|
seltype => cert_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
content => template($ne_ssl_privatekey_erb),
|
content => template($ne_ssl_privatekey_erb),
|
||||||
}
|
}
|
||||||
file { $ne_ssl_ca_cert_file:
|
file { $ne_ssl_ca_cert_file:
|
||||||
ensure => file,
|
ensure => file,
|
||||||
path => $ne_ssl_ca_cert_file,
|
path => $ne_ssl_ca_cert_file,
|
||||||
owner => $ne_user,
|
owner => 'root',
|
||||||
group => $ne_user,
|
group => 'root',
|
||||||
mode => '0440',
|
mode => '0644',
|
||||||
selrange => s0,
|
selrange => s0,
|
||||||
selrole => object_r,
|
selrole => object_r,
|
||||||
seltype => cert_t,
|
seltype => cert_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
content => template($ne_ssl_ca_cert_erb),
|
content => template($ne_ssl_ca_cert_erb),
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}</pre>
|
}</pre>
|
||||||
|
|||||||
@@ -349,6 +349,42 @@ inherited by all classes except defines.
|
|||||||
|
|
||||||
</li>
|
</li>
|
||||||
|
|
||||||
|
<li>
|
||||||
|
|
||||||
|
<span class='name'>ne_ssl_version</span>
|
||||||
|
|
||||||
|
|
||||||
|
<span class='type'>(<tt>String</tt>)</span>
|
||||||
|
|
||||||
|
|
||||||
|
<em class="default">(defaults to: <tt>'TLSv2+'</tt>)</em>
|
||||||
|
|
||||||
|
|
||||||
|
—
|
||||||
|
<div class='inline'>
|
||||||
|
<p>These directives allow you to specify how to use SSL/TLS.</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</li>
|
||||||
|
|
||||||
|
<li>
|
||||||
|
|
||||||
|
<span class='name'>ne_ssl_use_adh</span>
|
||||||
|
|
||||||
|
|
||||||
|
<span class='type'>(<tt>String</tt>)</span>
|
||||||
|
|
||||||
|
|
||||||
|
<em class="default">(defaults to: <tt>'1'</tt>)</em>
|
||||||
|
|
||||||
|
|
||||||
|
—
|
||||||
|
<div class='inline'>
|
||||||
|
<p>This is for backward compatibility and is DEPRECATED. Set to 1 to enable ADH or 2 to require ADH. 1 is currently the default but will be changed in a later version.</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</li>
|
||||||
|
|
||||||
<li>
|
<li>
|
||||||
|
|
||||||
<span class='name'>ne_ssl_cipher_list</span>
|
<span class='name'>ne_ssl_cipher_list</span>
|
||||||
@@ -367,6 +403,24 @@ inherited by all classes except defines.
|
|||||||
|
|
||||||
</li>
|
</li>
|
||||||
|
|
||||||
|
<li>
|
||||||
|
|
||||||
|
<span class='name'>ne_ssl_cacert_file</span>
|
||||||
|
|
||||||
|
|
||||||
|
<span class='type'>(<tt>String</tt>)</span>
|
||||||
|
|
||||||
|
|
||||||
|
<em class="default">(defaults to: <tt>'/etc/pki/tls/certs/ca-chain.crt.pem'</tt>)</em>
|
||||||
|
|
||||||
|
|
||||||
|
—
|
||||||
|
<div class='inline'>
|
||||||
|
<p>path and name of the ssl certificate authority (ca) file / chain. must be full path.</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</li>
|
||||||
|
|
||||||
<li>
|
<li>
|
||||||
|
|
||||||
<span class='name'>ne_ssl_client_certs</span>
|
<span class='name'>ne_ssl_client_certs</span>
|
||||||
@@ -375,7 +429,7 @@ inherited by all classes except defines.
|
|||||||
<span class='type'>(<tt>String</tt>)</span>
|
<span class='type'>(<tt>String</tt>)</span>
|
||||||
|
|
||||||
|
|
||||||
<em class="default">(defaults to: <tt>'0'</tt>)</em>
|
<em class="default">(defaults to: <tt>'2'</tt>)</em>
|
||||||
|
|
||||||
|
|
||||||
—
|
—
|
||||||
@@ -763,13 +817,6 @@ inherited by all classes except defines.
|
|||||||
<pre class="lines">
|
<pre class="lines">
|
||||||
|
|
||||||
|
|
||||||
82
|
|
||||||
83
|
|
||||||
84
|
|
||||||
85
|
|
||||||
86
|
|
||||||
87
|
|
||||||
88
|
|
||||||
89
|
89
|
||||||
90
|
90
|
||||||
91
|
91
|
||||||
@@ -855,10 +902,19 @@ inherited by all classes except defines.
|
|||||||
171
|
171
|
||||||
172
|
172
|
||||||
173
|
173
|
||||||
174</pre>
|
174
|
||||||
|
175
|
||||||
|
176
|
||||||
|
177
|
||||||
|
178
|
||||||
|
179
|
||||||
|
180
|
||||||
|
181
|
||||||
|
182
|
||||||
|
183</pre>
|
||||||
</td>
|
</td>
|
||||||
<td>
|
<td>
|
||||||
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 82</span>
|
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 89</span>
|
||||||
|
|
||||||
class confdroid_nrpe::params (
|
class confdroid_nrpe::params (
|
||||||
|
|
||||||
@@ -890,8 +946,11 @@ class confdroid_nrpe::params (
|
|||||||
String $ne_connection_timeout = '300',
|
String $ne_connection_timeout = '300',
|
||||||
String $ne_allow_weak_rnd_seed = '1',
|
String $ne_allow_weak_rnd_seed = '1',
|
||||||
Boolean $ne_enable_ssl = false,
|
Boolean $ne_enable_ssl = false,
|
||||||
|
String $ne_ssl_version = 'TLSv2+',
|
||||||
|
String $ne_ssl_use_adh = '1',
|
||||||
String $ne_ssl_cipher_list = 'ALL:!aNULL:!eNULL:!SSLv2:!LOW:!EXP:!RC4:!MD5:@STRENGTH',
|
String $ne_ssl_cipher_list = 'ALL:!aNULL:!eNULL:!SSLv2:!LOW:!EXP:!RC4:!MD5:@STRENGTH',
|
||||||
String $ne_ssl_client_certs = '0',
|
String $ne_ssl_cacert_file = '/etc/pki/tls/certs/ca-chain.crt.pem',
|
||||||
|
String $ne_ssl_client_certs = '2',
|
||||||
String $ne_ssl_logging = '0x00',
|
String $ne_ssl_logging = '0x00',
|
||||||
Array $ne_nasty_metachars = ["|`&><'\\[]{};\r\n"],
|
Array $ne_nasty_metachars = ["|`&><'\\[]{};\r\n"],
|
||||||
String $ne_include_file = '',
|
String $ne_include_file = '',
|
||||||
@@ -924,7 +983,6 @@ class confdroid_nrpe::params (
|
|||||||
# directories
|
# directories
|
||||||
$ne_main_conf_d_dir = '/etc/nrpe.d'
|
$ne_main_conf_d_dir = '/etc/nrpe.d'
|
||||||
$ne_run_dir = '/var/run/nrpe'
|
$ne_run_dir = '/var/run/nrpe'
|
||||||
$ne_servercert_dir = '/etc/pki/tls/servercerts'
|
|
||||||
|
|
||||||
# files
|
# files
|
||||||
$ne_main_conf_file = '/etc/nagios/nrpe.cfg'
|
$ne_main_conf_file = '/etc/nagios/nrpe.cfg'
|
||||||
@@ -943,11 +1001,11 @@ class confdroid_nrpe::params (
|
|||||||
$ne_checkmodule_nrpe_erb = 'confdroid_nrpe/checkmodule_nrpe.erb'
|
$ne_checkmodule_nrpe_erb = 'confdroid_nrpe/checkmodule_nrpe.erb'
|
||||||
$ne_nrpe_pp_file = "${ne_main_conf_d_dir}/nrpe.pp"
|
$ne_nrpe_pp_file = "${ne_main_conf_d_dir}/nrpe.pp"
|
||||||
$ne_semodule_erb = 'confdroid_nrpe/semodule_nrpe.erb'
|
$ne_semodule_erb = 'confdroid_nrpe/semodule_nrpe.erb'
|
||||||
$ne_ssl_cert_file = "${ne_servercert_dir}/nagios-cert.pem"
|
$ne_ssl_cert_file = "/etc/pki/tls/certs/${fqdn}.crt.pem"
|
||||||
$ne_ssl_cert_erb = 'confdroid_nrpe/ssl_cert.erb'
|
$ne_ssl_cert_erb = 'confdroid_nrpe/ssl_cert.erb'
|
||||||
$ne_ssl_privatekey_file = "${ne_servercert_dir}/nagios-key.pem"
|
$ne_ssl_privatekey_file = "/etc/pki/tls/private/${fqdn}.key.pem"
|
||||||
$ne_ssl_privatekey_erb = 'confdroid_nrpe/ssl_privatekey.erb'
|
$ne_ssl_privatekey_erb = 'confdroid_nrpe/ssl_privatekey.erb'
|
||||||
$ne_ssl_ca_cert_file = "${ne_servercert_dir}/ca-cert.pem"
|
$ne_ssl_ca_cert_file = "/etc/pki/tls/certs/${fqdn}-ca-chain.crt.pem"
|
||||||
$ne_ssl_ca_cert_erb = 'confdroid_nrpe/ssl_ca_cert.erb'
|
$ne_ssl_ca_cert_erb = 'confdroid_nrpe/ssl_ca_cert.erb'
|
||||||
|
|
||||||
# includes must be last
|
# includes must be last
|
||||||
|
|||||||
@@ -33,18 +33,4 @@ class confdroid_nrpe::main::dirs (
|
|||||||
seltype => var_run_t,
|
seltype => var_run_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
}
|
}
|
||||||
|
|
||||||
if $ne_enable_ssl {
|
|
||||||
file { $ne_servercert_dir:
|
|
||||||
ensure => directory,
|
|
||||||
path => $ne_servercert_dir,
|
|
||||||
owner => 'root',
|
|
||||||
group => 'root',
|
|
||||||
mode => '0755',
|
|
||||||
selrange => s0,
|
|
||||||
selrole => object_r,
|
|
||||||
seltype => cert_t,
|
|
||||||
seluser => system_u,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -41,6 +41,7 @@ class confdroid_nrpe::main::files (
|
|||||||
}
|
}
|
||||||
|
|
||||||
if $ne_allow_sudo == true {
|
if $ne_allow_sudo == true {
|
||||||
|
|
||||||
file { $ne_sudo_file:
|
file { $ne_sudo_file:
|
||||||
ensure => file,
|
ensure => file,
|
||||||
path => $ne_sudo_file,
|
path => $ne_sudo_file,
|
||||||
@@ -68,44 +69,45 @@ class confdroid_nrpe::main::files (
|
|||||||
content => template($ne_nrpe_te_erb),
|
content => template($ne_nrpe_te_erb),
|
||||||
notify => Exec['create_nrpe_pp'],
|
notify => Exec['create_nrpe_pp'],
|
||||||
}
|
}
|
||||||
}
|
|
||||||
# file for ssl certificate
|
# file for ssl certificate
|
||||||
if $ne_enable_ssl == true {
|
if $ne_enable_ssl == true {
|
||||||
file { $ne_ssl_cert_file:
|
file { $ne_ssl_cert_file:
|
||||||
ensure => file,
|
ensure => file,
|
||||||
path => $ne_ssl_cert_file,
|
path => $ne_ssl_cert_file,
|
||||||
owner => $ne_user,
|
owner => 'root',
|
||||||
group => $ne_user,
|
group => 'root',
|
||||||
mode => '0440',
|
mode => '0644',
|
||||||
selrange => s0,
|
selrange => s0,
|
||||||
selrole => object_r,
|
selrole => object_r,
|
||||||
seltype => cert_t,
|
seltype => cert_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
content => template($ne_ssl_cert_erb),
|
content => template($ne_ssl_cert_erb),
|
||||||
}
|
}
|
||||||
file { $ne_ssl_privatekey_file:
|
file { $ne_ssl_privatekey_file:
|
||||||
ensure => file,
|
ensure => file,
|
||||||
path => $ne_ssl_privatekey_file,
|
path => $ne_ssl_privatekey_file,
|
||||||
owner => $ne_user,
|
owner => 'root',
|
||||||
group => $ne_user,
|
group => 'root',
|
||||||
mode => '0400',
|
mode => '0600',
|
||||||
selrange => s0,
|
selrange => s0,
|
||||||
selrole => object_r,
|
selrole => object_r,
|
||||||
seltype => cert_t,
|
seltype => cert_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
content => template($ne_ssl_privatekey_erb),
|
content => template($ne_ssl_privatekey_erb),
|
||||||
}
|
}
|
||||||
file { $ne_ssl_ca_cert_file:
|
file { $ne_ssl_ca_cert_file:
|
||||||
ensure => file,
|
ensure => file,
|
||||||
path => $ne_ssl_ca_cert_file,
|
path => $ne_ssl_ca_cert_file,
|
||||||
owner => $ne_user,
|
owner => 'root',
|
||||||
group => $ne_user,
|
group => 'root',
|
||||||
mode => '0440',
|
mode => '0644',
|
||||||
selrange => s0,
|
selrange => s0,
|
||||||
selrole => object_r,
|
selrole => object_r,
|
||||||
seltype => cert_t,
|
seltype => cert_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
content => template($ne_ssl_ca_cert_erb),
|
content => template($ne_ssl_ca_cert_erb),
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -30,9 +30,16 @@
|
|||||||
# daemon will allow plugins to finish executing before killing them off.
|
# daemon will allow plugins to finish executing before killing them off.
|
||||||
# @param [String] ne_connection_timeout maximum number of seconds that the
|
# @param [String] ne_connection_timeout maximum number of seconds that the
|
||||||
# NRPE daemon will wait for a connection to be established before exiting.
|
# NRPE daemon will wait for a connection to be established before exiting.
|
||||||
|
# @param [String] ne_ssl_version These directives allow you to specify how to
|
||||||
|
# use SSL/TLS.
|
||||||
|
# @param [String] ne_ssl_use_adh This is for backward compatibility and is
|
||||||
|
# DEPRECATED. Set to 1 to enable ADH or 2 to require ADH. 1 is currently the
|
||||||
|
# default but will be changed in a later version.
|
||||||
# @param [String] ne_ssl_cipher_list ciphers can be used. For backward
|
# @param [String] ne_ssl_cipher_list ciphers can be used. For backward
|
||||||
# compatibility, this defaults to 'ssl_cipher_list=ALL:!MD5:@STRENGTH' in
|
# compatibility, this defaults to 'ssl_cipher_list=ALL:!MD5:@STRENGTH' in
|
||||||
# this version but will be changed in a later version of NRPE.
|
# this version but will be changed in a later version of NRPE.
|
||||||
|
# @param [String] ne_ssl_cacert_file path and name of the ssl certificate
|
||||||
|
# authority (ca) file / chain. must be full path.
|
||||||
# @param [String] ne_ssl_client_certs determines client certificate usage.
|
# @param [String] ne_ssl_client_certs determines client certificate usage.
|
||||||
# Values: 0 = Don't ask for or require client certificates
|
# Values: 0 = Don't ask for or require client certificates
|
||||||
# 1 = Ask for client certificates
|
# 1 = Ask for client certificates
|
||||||
@@ -109,8 +116,11 @@ class confdroid_nrpe::params (
|
|||||||
String $ne_connection_timeout = '300',
|
String $ne_connection_timeout = '300',
|
||||||
String $ne_allow_weak_rnd_seed = '1',
|
String $ne_allow_weak_rnd_seed = '1',
|
||||||
Boolean $ne_enable_ssl = false,
|
Boolean $ne_enable_ssl = false,
|
||||||
|
String $ne_ssl_version = 'TLSv2+',
|
||||||
|
String $ne_ssl_use_adh = '1',
|
||||||
String $ne_ssl_cipher_list = 'ALL:!aNULL:!eNULL:!SSLv2:!LOW:!EXP:!RC4:!MD5:@STRENGTH',
|
String $ne_ssl_cipher_list = 'ALL:!aNULL:!eNULL:!SSLv2:!LOW:!EXP:!RC4:!MD5:@STRENGTH',
|
||||||
String $ne_ssl_client_certs = '0',
|
String $ne_ssl_cacert_file = '/etc/pki/tls/certs/ca-chain.crt.pem',
|
||||||
|
String $ne_ssl_client_certs = '2',
|
||||||
String $ne_ssl_logging = '0x00',
|
String $ne_ssl_logging = '0x00',
|
||||||
Array $ne_nasty_metachars = ["|`&><'\\[]{};\r\n"],
|
Array $ne_nasty_metachars = ["|`&><'\\[]{};\r\n"],
|
||||||
String $ne_include_file = '',
|
String $ne_include_file = '',
|
||||||
@@ -143,7 +153,6 @@ class confdroid_nrpe::params (
|
|||||||
# directories
|
# directories
|
||||||
$ne_main_conf_d_dir = '/etc/nrpe.d'
|
$ne_main_conf_d_dir = '/etc/nrpe.d'
|
||||||
$ne_run_dir = '/var/run/nrpe'
|
$ne_run_dir = '/var/run/nrpe'
|
||||||
$ne_servercert_dir = '/etc/pki/tls/servercerts'
|
|
||||||
|
|
||||||
# files
|
# files
|
||||||
$ne_main_conf_file = '/etc/nagios/nrpe.cfg'
|
$ne_main_conf_file = '/etc/nagios/nrpe.cfg'
|
||||||
@@ -162,11 +171,11 @@ class confdroid_nrpe::params (
|
|||||||
$ne_checkmodule_nrpe_erb = 'confdroid_nrpe/checkmodule_nrpe.erb'
|
$ne_checkmodule_nrpe_erb = 'confdroid_nrpe/checkmodule_nrpe.erb'
|
||||||
$ne_nrpe_pp_file = "${ne_main_conf_d_dir}/nrpe.pp"
|
$ne_nrpe_pp_file = "${ne_main_conf_d_dir}/nrpe.pp"
|
||||||
$ne_semodule_erb = 'confdroid_nrpe/semodule_nrpe.erb'
|
$ne_semodule_erb = 'confdroid_nrpe/semodule_nrpe.erb'
|
||||||
$ne_ssl_cert_file = "${ne_servercert_dir}/nagios-cert.pem"
|
$ne_ssl_cert_file = "/etc/pki/tls/certs/${fqdn}.crt.pem"
|
||||||
$ne_ssl_cert_erb = 'confdroid_nrpe/ssl_cert.erb'
|
$ne_ssl_cert_erb = 'confdroid_nrpe/ssl_cert.erb'
|
||||||
$ne_ssl_privatekey_file = "${ne_servercert_dir}/nagios-key.pem"
|
$ne_ssl_privatekey_file = "/etc/pki/tls/private/${fqdn}.key.pem"
|
||||||
$ne_ssl_privatekey_erb = 'confdroid_nrpe/ssl_privatekey.erb'
|
$ne_ssl_privatekey_erb = 'confdroid_nrpe/ssl_privatekey.erb'
|
||||||
$ne_ssl_ca_cert_file = "${ne_servercert_dir}/ca-cert.pem"
|
$ne_ssl_ca_cert_file = "/etc/pki/tls/certs/${fqdn}-ca-chain.crt.pem"
|
||||||
$ne_ssl_ca_cert_erb = 'confdroid_nrpe/ssl_ca_cert.erb'
|
$ne_ssl_ca_cert_erb = 'confdroid_nrpe/ssl_ca_cert.erb'
|
||||||
|
|
||||||
# includes must be last
|
# includes must be last
|
||||||
|
|||||||
@@ -33,9 +33,11 @@ connection_timeout=<%= @ne_connection_timeout %>
|
|||||||
|
|
||||||
allow_weak_random_seed=<%= @ne_allow_weak_rnd_seed %>
|
allow_weak_random_seed=<%= @ne_allow_weak_rnd_seed %>
|
||||||
|
|
||||||
<% if @ne_enable_ssl == true -%>
|
<% if $ne_enable_ssl == true -%>
|
||||||
|
ssl_version=<%= @ne_ssl_version %>
|
||||||
|
ssl_use_adh=<%= @ne_ssl_use_adh %>
|
||||||
ssl_cipher_list=<%= @ne_ssl_cipher_list %>
|
ssl_cipher_list=<%= @ne_ssl_cipher_list %>
|
||||||
ssl_cacert_file=<%= @ne_ssl_ca_cert_file %>
|
ssl_cacert_file=<%= @ne_ssl_cacert_file %>
|
||||||
ssl_cert_file=<%= @ne_ssl_cert_file %>
|
ssl_cert_file=<%= @ne_ssl_cert_file %>
|
||||||
ssl_privatekey_file=<%= @ne_ssl_privatekey_file %>
|
ssl_privatekey_file=<%= @ne_ssl_privatekey_file %>
|
||||||
ssl_client_certs=<%= @ne_ssl_client_certs %>
|
ssl_client_certs=<%= @ne_ssl_client_certs %>
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
<% unless @ne_ssl_ca_cert_pem.nil? || @ne_ssl_ca_cert_pem.empty? -%>
|
<% unless @ne_ssl_ca_cert_pem.nil -%>
|
||||||
<%= @ne_ssl_ca_cert_pem %>
|
<%= @ne_ssl_ca_cert_pem %>
|
||||||
<% end -%>
|
<% end -%>
|
||||||
@@ -1,3 +1,3 @@
|
|||||||
<% unless @ne_ssl_cert_pem.nil? || @ne_ssl_cert_pem.empty? -%>
|
<% unless @ne_ssl_cert_pem.nil -%>
|
||||||
<%= @ne_ssl_cert_pem %>
|
<%= @ne_ssl_cert_pem %>
|
||||||
<% end -%>
|
<% end -%>
|
||||||
@@ -1,3 +1,3 @@
|
|||||||
<% unless @ne_ssl_privatekey_pem.nil? || @ne_ssl_privatekey_pem.empty? -%>
|
<% unless @ne_ssl_privatekey_pem.nil -%>
|
||||||
<%= @ne_ssl_privatekey_pem %>
|
<%= @ne_ssl_privatekey_pem %>
|
||||||
<% end -%>
|
<% end -%>
|
||||||
Reference in New Issue
Block a user