2009-09-29 19:53:04 +02:00
|
|
|
# wrapper to have some defaults.
|
|
|
|
define sshd::ssh_authorized_key(
|
2009-12-18 18:36:05 +01:00
|
|
|
$ensure = 'present',
|
2009-09-29 19:53:04 +02:00
|
|
|
$type = 'ssh-dss',
|
2009-12-18 19:06:43 +01:00
|
|
|
$key = 'absent',
|
2011-01-20 08:25:32 +01:00
|
|
|
$user = '',
|
2009-12-10 23:15:07 +01:00
|
|
|
$target = undef,
|
2015-05-20 23:55:09 +02:00
|
|
|
$options = 'absent',
|
|
|
|
$override_builtin = undef
|
2009-09-29 19:53:04 +02:00
|
|
|
){
|
|
|
|
|
2009-12-18 19:06:43 +01:00
|
|
|
if ($ensure=='present') and ($key=='absent') {
|
|
|
|
fail("You have to set \$key for Sshd::Ssh_authorized_key[${name}]!")
|
|
|
|
}
|
|
|
|
|
2009-12-10 23:15:07 +01:00
|
|
|
$real_user = $user ? {
|
2013-02-03 00:30:54 +01:00
|
|
|
false => $name,
|
|
|
|
'' => $name,
|
2009-12-10 23:15:07 +01:00
|
|
|
default => $user,
|
|
|
|
}
|
|
|
|
|
|
|
|
case $target {
|
2009-12-10 23:34:57 +01:00
|
|
|
undef,'': {
|
|
|
|
case $real_user {
|
2009-12-10 23:15:07 +01:00
|
|
|
'root': { $real_target = '/root/.ssh/authorized_keys' }
|
2011-01-20 02:45:59 +01:00
|
|
|
default: { $real_target = "/home/${real_user}/.ssh/authorized_keys" }
|
2009-12-10 23:15:07 +01:00
|
|
|
}
|
2009-09-29 19:53:04 +02:00
|
|
|
}
|
2009-12-10 23:15:07 +01:00
|
|
|
default: {
|
|
|
|
$real_target = $target
|
2009-09-29 19:53:04 +02:00
|
|
|
}
|
2009-12-10 23:15:07 +01:00
|
|
|
}
|
2009-09-29 19:53:04 +02:00
|
|
|
|
2015-05-20 23:55:09 +02:00
|
|
|
# The ssh_authorized_key built-in function (in 2.7.23 at least)
|
|
|
|
# will not write an authorized_keys file for a mortal user to
|
|
|
|
# a directory they don't have write permission to, puppet attempts to
|
|
|
|
# create the file as the user specified with the user parameter and fails.
|
|
|
|
# Since ssh will refuse to use authorized_keys files not owned by the
|
|
|
|
# user, or in files/directories that allow other users to write, this
|
|
|
|
# behavior is deliberate in order to prevent typical non-working
|
|
|
|
# configurations. However, it also prevents the case of puppet, running
|
|
|
|
# as root, writing a file owned by a mortal user to a common
|
|
|
|
# authorized_keys directory such as one might specify in sshd_config with
|
|
|
|
# something like
|
|
|
|
# 'AuthorizedKeysFile /etc/ssh/authorized_keys/%u'
|
|
|
|
# So we provide a way to override the built-in and instead just install
|
|
|
|
# via a file resource. There is no additional security risk here, it's
|
|
|
|
# nothing a user can't already do by writing their own file resources,
|
|
|
|
# we still depend on the filesystem permissions to keep things safe.
|
|
|
|
if $override_builtin {
|
|
|
|
case $options {
|
|
|
|
'absent': {
|
|
|
|
info("not setting any option for ssh_authorized_key: ${name}")
|
2015-05-21 16:17:52 +02:00
|
|
|
$header = "# HEADER: This file is managed by Puppet.\n"
|
2015-05-20 23:55:09 +02:00
|
|
|
|
2015-05-21 15:56:59 +02:00
|
|
|
file { $real_target:
|
2015-05-20 23:55:09 +02:00
|
|
|
ensure => $ensure,
|
2015-05-21 16:17:52 +02:00
|
|
|
content => "${header}${type} ${key}",
|
2015-05-21 15:56:59 +02:00
|
|
|
owner => $real_user,
|
2015-05-20 23:55:09 +02:00
|
|
|
mode => '0600';
|
|
|
|
}
|
|
|
|
}
|
|
|
|
default: {
|
2015-05-21 15:56:59 +02:00
|
|
|
file { $real_target:
|
2015-05-20 23:55:09 +02:00
|
|
|
ensure => $ensure,
|
2015-05-21 16:17:52 +02:00
|
|
|
content => "${header}${options} ${type} ${key}",
|
2015-05-21 15:56:59 +02:00
|
|
|
owner => $real_user,
|
2015-05-20 23:55:09 +02:00
|
|
|
mode => '0600';
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
ssh_authorized_key{$name:
|
|
|
|
ensure => $ensure,
|
|
|
|
type => $type,
|
|
|
|
key => $key,
|
|
|
|
user => $real_user,
|
|
|
|
target => $real_target,
|
|
|
|
}
|
|
|
|
|
|
|
|
case $options {
|
|
|
|
'absent': {
|
|
|
|
info("not setting any option for ssh_authorized_key: ${name}")
|
|
|
|
}
|
|
|
|
default: {
|
|
|
|
Ssh_authorized_key[$name]{
|
|
|
|
options => $options,
|
|
|
|
}
|
2009-12-10 23:15:07 +01:00
|
|
|
}
|
2009-09-29 19:53:04 +02:00
|
|
|
}
|
2009-12-10 23:15:07 +01:00
|
|
|
}
|
2009-09-29 19:53:04 +02:00
|
|
|
}
|