Commit Graph

543 Commits

Author SHA1 Message Date
Adam Mendlik 154213560f Correct typo in .kitchen.yml
This change has no impact on the kitchen tests, but only changes
a symbolic name from 'openssl' to 'openssh' to avoid confusion.
2017-04-21 11:57:01 -06:00
alxwr 844e96b57b Merge pull request #88 from alxwr/force_key_length
Opt-in to enforce RSA key length
2017-03-07 20:24:34 +01:00
alxwr 9fddb0ea2a Merge pull request #87 from alxwr/auth_map
openssh.auth_map
2017-03-07 20:24:26 +01:00
Alexander Weidinger 6b23b28f52 Opt-in to enforce RSA key length 2017-03-04 14:21:58 +01:00
Alexander Weidinger 674216d0ad openssh.auth_map 2017-03-04 14:21:53 +01:00
Alexander Weidinger 66c954ed66 Set correct ssh(d)_config_group for *BSD 2017-03-04 14:20:07 +01:00
Niels Abspoel 4ec97eeb28 Merge pull request #86 from amendlik/file-mode
Add variables for file owner and mode
2017-02-25 14:47:58 +01:00
amendlik 6d6c7a0ead Merge branch 'master' into file-mode 2017-02-25 06:40:30 -07:00
Niels Abspoel 044d4d646b Merge pull request #81 from leansalt/pillar-example-update
Add secure defaults to pillar.example + secure sshd_config in defaults.yml #66
2017-02-25 12:30:37 +01:00
Adam Mendlik b3fd60f016 Test using default permissions for ssh_config 2017-02-24 13:39:59 -07:00
ek9 038a51cdc8 manage sshd_config and ssh_config only if pillars are defined 2017-02-24 21:13:52 +01:00
ek9 c03e29a498 remove Kex,MACs,Ciphers from defaults 2017-02-24 21:13:35 +01:00
ek9 f192b91192 add more verbose warnings regarding ssh_config in pillar.example 2017-02-24 20:17:36 +01:00
Adam Mendlik 613bea2cac Add variables for file owner and mode 2017-02-23 14:56:22 -07:00
Niels Abspoel b0afda98ed Merge pull request #85 from amendlik/test-kitchen
Add test-kitchen configuration
2017-02-23 22:52:16 +01:00
Adam Mendlik 14cc19c941 Add test-kitchen configuration 2017-02-23 14:04:27 -07:00
Alexander Weidinger 70461403cb known_hosts: sort IP addresses
in order to prevent unnecessary changes due to
random ordering of dig results.
2017-02-23 03:59:40 +01:00
Alexander Weidinger 678cc9066c PrintLastLog missing in FreeBSD 10.3 2017-02-23 01:19:21 +01:00
ek9 f5a74f3fa0 defaults: enable secure defaults on sshd_config 2017-02-19 14:45:12 +01:00
ek9 ec796662bc pillar.example: update with secure defaults for sshd_config and ssh_config 2017-02-19 14:44:56 +01:00
ek9 d6e48f2b43 rebase based on latest update 2017-02-07 19:45:59 +01:00
Javier Bértoli 2db9253c45 Merge pull request #82 from pepoluan/allow_list_or_string
Allow list or string for some option, and setting of ConfigBanner
2017-02-07 07:26:44 -03:00
Javier Bértoli 893b96d023 Merge pull request #83 from llua/redhat
setup sftp correctly on RedHat-like machines
2017-01-24 20:55:17 -03:00
Eric Cook f4ea96f9c1 setup sftp correctly on RedHat-like machines 2017-01-24 18:17:15 -05:00
Pandu E Poluan 18e1866ac5 Update pillar.example
`pillar.example` now contains information on how to use the
'string-or-list' feature for some options.

Also an explanation on the new `ConfigBanner` option.
2017-01-24 01:43:04 +07:00
Pandu E Poluan 773d9ae092 Apply string-or-list processing to ssh_config
Now ssh_config also accepts string-or-list options, for serveral
keywords.
2017-01-24 01:34:24 +07:00
Pandu E Poluan 30648d115e Add macro to handle string or list
Added a macro to handle multivalue options entered in either string
format or list format (with auto joiner).
2017-01-24 01:17:51 +07:00
Brian Jackson b9689cedff Merge pull request #79 from leansalt/server-service-control
Add ability to control SSH server service status (default: on)
2017-01-15 21:48:04 -08:00
Florian Ermisch bff3e5d199 Merge pull request #80 from llua/use_pam
do not set UsePAM on OpenBSD
2017-01-15 12:04:07 +01:00
Eric Cook 686fc2c4ee do not set UsePAM on OpenBSD
Upstream opensshd does not support PAM
2017-01-14 18:38:37 -05:00
Forrest 086937b84f Merge pull request #76 from freach/master
openssh.auth will produce invalid SLS definition if sshd_config configs are missing
2016-11-02 09:06:07 -07:00
Simon Pirschel 1b69ecab2c fix issue with stripping new line will result in invalid SLS definition if AuthorizedKeysFile is missing in sshd_config 2016-11-02 15:21:50 +01:00
Forrest 0c06e247d5 Merge pull request #75 from freach/master
sshd won't start if AddressFamily option is specified
2016-11-01 09:09:49 -07:00
Simon Pirschel 2a1b8fbc66 fix issue sshd won't start if AddressFamily is specified, because it must be defined before ListenAddress 2016-11-01 13:24:30 +01:00
Forrest ec663a6f5e Merge pull request #51 from mathieupotier/master
Put ssh keys on configured path in sshd_config (AuthorizedKeysFile)
2016-10-31 09:32:50 -07:00
Forrest 263575e57e Merge pull request #74 from llua/arch_sftp
fix Subsystem directive on archlinux
2016-10-29 21:15:46 -07:00
Eric Cook 51fd8b1391 fix Subsystem directive on archlinux 2016-10-30 00:06:02 -04:00
Forrest 8c1d02f249 Merge pull request #73 from omltorg/updated_archlinux_pkg_name
Update name of package containing dig on ArchLinux
2016-10-14 16:17:59 -07:00
omltorg de66dbee97 Update name of package containing dig on ArchLinux 2016-10-14 22:25:56 +00:00
Forrest 8d1e730907 Merge pull request #72 from kyrias/AuthKeysCmd
Add AuthorizedKeysCommand support
2016-10-02 11:59:37 -07:00
Johannes Löthberg a74d859992 Add AuthorizedKeysCommand to pillar.example
Signed-off-by: Johannes Löthberg <johannes@kyriasis.com>
2016-10-02 10:37:11 +02:00
Johannes Löthberg 02b52fa7cf Add AuthorizedKeysCommand support
Signed-off-by: Johannes Löthberg <johannes@kyriasis.com>
2016-10-01 20:53:44 +02:00
Forrest 329a762e01 Merge pull request #71 from BT-dschleich/patch-1
Fix mine function example in README.rst
2016-09-08 09:11:50 -07:00
Dominik Schleich 7113243334 Fix mine function example in README.rst
like it was already done in the pillar.example in this PR https://github.com/saltstack-formulas/openssh-formula/pull/36 to avoid confusions.
2016-09-08 13:28:22 +02:00
Mathieu POTIER 760a2ad277 fix the path to authkeys
Allow user to specify aliased path (with %u)
2016-08-02 09:54:46 +02:00
Mathieu POTIER 4c814843f8 Merge remote-tracking branch 'refs/remotes/saltstack-formulas/master' 2016-08-02 09:46:08 +02:00
Forrest 5e979f3843 Merge pull request #69 from pepoluan/pepoluan-moduli_pull
Allow moduli to be pulled as file
2016-08-01 10:14:30 -07:00
Pandu E Poluan 11ba2acea7 Give information on using moduli_source
Give additional comments to inform that moduli can also be provided via a file, using the moduli_source key.
2016-08-02 00:03:14 +07:00
Pandu E Poluan e6603ae62a Allow moduli to be pulled as file
Added Jinja logic to allow the option to pull the moduli from an online source.
2016-08-01 23:59:11 +07:00
Forrest 8ea31fd661 Merge pull request #68 from levlozhkin/master
Convert dig exist check to unless req to remove spurious change in report
2016-07-19 13:46:56 -07:00