add ufw rule for ssh
This commit is contained in:
parent
e30654474e
commit
8c371f2886
3 changed files with 14 additions and 20 deletions
|
@ -532,6 +532,7 @@ natpub-1.komreg.net:
|
||||||
autoupdate:
|
autoupdate:
|
||||||
md_publisher:
|
md_publisher:
|
||||||
keyname: natpub-1.komreg.net_infra
|
keyname: natpub-1.komreg.net_infra
|
||||||
|
signer_ip_adress: '94.176.224.197'
|
||||||
sunet::frontend::register_sites:
|
sunet::frontend::register_sites:
|
||||||
sites:
|
sites:
|
||||||
'md.swedenconnect.se':
|
'md.swedenconnect.se':
|
||||||
|
@ -558,6 +559,7 @@ eupub-1.komreg.net:
|
||||||
autoupdate:
|
autoupdate:
|
||||||
md_publisher:
|
md_publisher:
|
||||||
keyname: eupub-1.komreg.net_infra
|
keyname: eupub-1.komreg.net_infra
|
||||||
|
signer_ip_adress: '94.176.224.198'
|
||||||
mdsl_publisher:
|
mdsl_publisher:
|
||||||
sunet::frontend::register_sites:
|
sunet::frontend::register_sites:
|
||||||
sites:
|
sites:
|
||||||
|
@ -571,6 +573,7 @@ eupub-test-1.komreg.net:
|
||||||
autoupdate:
|
autoupdate:
|
||||||
md_publisher:
|
md_publisher:
|
||||||
keyname: eupub-test-1.komreg.net_infra
|
keyname: eupub-test-1.komreg.net_infra
|
||||||
|
signer_ip_adress: '89.45.237.138'
|
||||||
mdsl_publisher:
|
mdsl_publisher:
|
||||||
sunet::frontend::register_sites:
|
sunet::frontend::register_sites:
|
||||||
sites:
|
sites:
|
||||||
|
@ -628,6 +631,7 @@ natpub-2.komreg.net:
|
||||||
autoupdate:
|
autoupdate:
|
||||||
md_publisher:
|
md_publisher:
|
||||||
keyname: natpub-2.komreg.net_infra
|
keyname: natpub-2.komreg.net_infra
|
||||||
|
signer_ip_adress: '94.176.224.69'
|
||||||
sunet::frontend::register_sites:
|
sunet::frontend::register_sites:
|
||||||
sites:
|
sites:
|
||||||
'md.swedenconnect.se':
|
'md.swedenconnect.se':
|
||||||
|
@ -640,6 +644,7 @@ natpub-test-2.komreg.net:
|
||||||
autoupdate:
|
autoupdate:
|
||||||
md_publisher:
|
md_publisher:
|
||||||
keyname: natpub-test-2.komreg.net_infra
|
keyname: natpub-test-2.komreg.net_infra
|
||||||
|
signer_ip_adress: '89.45.237.80'
|
||||||
mdsl_publisher:
|
mdsl_publisher:
|
||||||
sunet::frontend::register_sites:
|
sunet::frontend::register_sites:
|
||||||
sites:
|
sites:
|
||||||
|
@ -653,6 +658,7 @@ eupub-2.komreg.net:
|
||||||
autoupdate:
|
autoupdate:
|
||||||
md_publisher:
|
md_publisher:
|
||||||
keyname: eupub-2.komreg.net_infra
|
keyname: eupub-2.komreg.net_infra
|
||||||
|
signer_ip_adress: '94.176.224.70'
|
||||||
mdsl_publisher:
|
mdsl_publisher:
|
||||||
sunet::frontend::register_sites:
|
sunet::frontend::register_sites:
|
||||||
sites:
|
sites:
|
||||||
|
@ -666,6 +672,7 @@ eupub-test-2.komreg.net:
|
||||||
autoupdate:
|
autoupdate:
|
||||||
md_publisher:
|
md_publisher:
|
||||||
keyname: eupub-test-2.komreg.net_infra
|
keyname: eupub-test-2.komreg.net_infra
|
||||||
|
signer_ip_adress: '89.45.236.73'
|
||||||
mdsl_publisher:
|
mdsl_publisher:
|
||||||
sunet::frontend::register_sites:
|
sunet::frontend::register_sites:
|
||||||
sites:
|
sites:
|
||||||
|
@ -697,6 +704,7 @@ p1.komreg.net:
|
||||||
autoupdate:
|
autoupdate:
|
||||||
md_publisher:
|
md_publisher:
|
||||||
keyname: p1.komreg.net_infra
|
keyname: p1.komreg.net_infra
|
||||||
|
signer_ip_adress: '89.45.233.92'
|
||||||
sunet::frontend::register_sites:
|
sunet::frontend::register_sites:
|
||||||
sites:
|
sites:
|
||||||
'qa.md.swedenconnect.se':
|
'qa.md.swedenconnect.se':
|
||||||
|
@ -710,6 +718,7 @@ p2.qa.komreg.net:
|
||||||
autoupdate:
|
autoupdate:
|
||||||
md_publisher:
|
md_publisher:
|
||||||
keyname: p2.qa.komreg.net_infra
|
keyname: p2.qa.komreg.net_infra
|
||||||
|
signer_ip_adress: '89.45.233.208'
|
||||||
mdsl_publisher:
|
mdsl_publisher:
|
||||||
sunet::frontend::register_sites:
|
sunet::frontend::register_sites:
|
||||||
sites:
|
sites:
|
||||||
|
|
|
@ -227,7 +227,7 @@ class md_signer($dest_host=undef,$dest_dir="",$version="eidas") {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
class md_publisher(Array $allow_clients=['any'], $keyname=undef, String $dir="/var/www/html") {
|
class md_publisher(Array $allow_clients=['any'], $keyname=undef, String $dir="/var/www/html", $signer_ip_adress=undef) {
|
||||||
$_keyname = $keyname ? {
|
$_keyname = $keyname ? {
|
||||||
undef => $::fqdn,
|
undef => $::fqdn,
|
||||||
default => $keyname
|
default => $keyname
|
||||||
|
@ -272,6 +272,10 @@ class md_publisher(Array $allow_clients=['any'], $keyname=undef, String $dir="/v
|
||||||
warning_age => '600',
|
warning_age => '600',
|
||||||
critical_age => '86400'
|
critical_age => '86400'
|
||||||
}
|
}
|
||||||
|
sunet::misc::ufw_allow { "allow_ssh":
|
||||||
|
from => $signer_ip_adress,
|
||||||
|
port => '22',
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
class mdsl_publisher() {
|
class mdsl_publisher() {
|
||||||
|
|
|
@ -1,19 +0,0 @@
|
||||||
class eid::ssh_rules{
|
|
||||||
|
|
||||||
$servers = ['nat', 'eu']
|
|
||||||
$servers.each |$servers|{
|
|
||||||
if $::fqdn == ${server}pub-test-1.komreg.net {
|
|
||||||
sunet::misc::ufw_allow { 'allow_${key}_ssh_1':
|
|
||||||
from => dnsLookup(${server}md-test-1.komreg.net)
|
|
||||||
port => '22',
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if $::fqdn == ${server}pub-test-2.komreg.net {
|
|
||||||
sunet::misc::ufw_allow { 'allow_${key}_ssh_2':
|
|
||||||
from => dnsLookup(${server}md-test-2.komreg.net)
|
|
||||||
port => '22',
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
}
|
|
Loading…
Add table
Reference in a new issue