diff options
author | Jenkins <jenkins@review.openstack.org> | 2017-01-04 02:37:57 +0000 |
---|---|---|
committer | Gerrit Code Review <review@openstack.org> | 2017-01-04 02:37:57 +0000 |
commit | 71af301fc5c60c1cccb66dbfc630713c947a94d3 (patch) | |
tree | 185a7e8523ec74e8e868e90310365402c1939a58 /manifests | |
parent | 9e0ce7cf4eb6079657608ecce222d97f5e5f8442 (diff) | |
parent | 5a1764acf7623ee04d8610793f418ab1d4e2226e (diff) |
Merge "Adds ability to populate SSH Banner text"
Diffstat (limited to 'manifests')
-rw-r--r-- | manifests/profile/base/sshd.pp | 61 |
1 files changed, 61 insertions, 0 deletions
diff --git a/manifests/profile/base/sshd.pp b/manifests/profile/base/sshd.pp new file mode 100644 index 0000000..e7916c1 --- /dev/null +++ b/manifests/profile/base/sshd.pp @@ -0,0 +1,61 @@ +# Copyright 2016 Red Hat, Inc. +# All Rights Reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); you may +# not use this file except in compliance with the License. You may obtain +# a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT +# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the +# License for the specific language governing permissions and limitations +# under the License. +# +# == Class: tripleo::profile::base::sshd +# +# SSH profile for tripleo +# +# === Parameters +# +# [*bannertext*] +# The text used within SSH Banner +# Defaults to hiera('BannerText') +# +class tripleo::profile::base::sshd ( + $bannertext = hiera('BannerText', undef), +) { + + if $bannertext { + $action = 'set' + } else { + $action = 'rm' + } + + package {'openssh-server': + ensure => installed, + } + + augeas { 'sshd_config_banner': + context => '/files/etc/ssh/sshd_config', + changes => [ "${action} Banner /etc/issue" ], + notify => Service['sshd'] + } + + file { '/etc/issue': + ensure => file, + backup => false, + content => $bannertext, + owner => 'root', + group => 'root', + mode => '0600' + } + + service { 'sshd': + ensure => 'running', + enable => true, + hasstatus => false, + require => Package['openssh-server'], + } +} |