Adam Mendlik
0c363d284e
Update tests for compatibility with recent changes
Commit 038a51cdc8
introduced a change
where the sshd_config file is not managed unless the 'sshd_config'
pillar variable is defined. The kitchen tests did not define that
variable, so they stopped working.
This change sets a default value for 'Port' so the file is managed
by Salt.
7 years ago
Adam Mendlik
154213560f
Correct typo in .kitchen.yml
This change has no impact on the kitchen tests, but only changes
a symbolic name from 'openssl' to 'openssh' to avoid confusion.
7 years ago
alxwr
844e96b57b
Merge pull request #88 from alxwr/force_key_length
Opt-in to enforce RSA key length
7 years ago
alxwr
9fddb0ea2a
Merge pull request #87 from alxwr/auth_map
openssh.auth_map
7 years ago
Alexander Weidinger
6b23b28f52
Opt-in to enforce RSA key length
7 years ago
Alexander Weidinger
674216d0ad
openssh.auth_map
7 years ago
Alexander Weidinger
66c954ed66
Set correct ssh(d)_config_group for *BSD
7 years ago
Niels Abspoel
4ec97eeb28
Merge pull request #86 from amendlik/file-mode
Add variables for file owner and mode
7 years ago
amendlik
6d6c7a0ead
Merge branch 'master' into file-mode
7 years ago
Niels Abspoel
044d4d646b
Merge pull request #81 from leansalt/pillar-example-update
Add secure defaults to pillar.example + secure sshd_config in defaults.yml #66
7 years ago
Adam Mendlik
b3fd60f016
Test using default permissions for ssh_config
7 years ago
ek9
038a51cdc8
manage sshd_config and ssh_config only if pillars are defined
7 years ago
ek9
c03e29a498
remove Kex,MACs,Ciphers from defaults
7 years ago
ek9
f192b91192
add more verbose warnings regarding ssh_config in pillar.example
7 years ago
Adam Mendlik
613bea2cac
Add variables for file owner and mode
7 years ago
Niels Abspoel
b0afda98ed
Merge pull request #85 from amendlik/test-kitchen
Add test-kitchen configuration
7 years ago
Adam Mendlik
14cc19c941
Add test-kitchen configuration
7 years ago
Alexander Weidinger
70461403cb
known_hosts: sort IP addresses
in order to prevent unnecessary changes due to
random ordering of dig results.
7 years ago
Alexander Weidinger
678cc9066c
PrintLastLog missing in FreeBSD 10.3
7 years ago
ek9
f5a74f3fa0
defaults: enable secure defaults on sshd_config
7 years ago
ek9
ec796662bc
pillar.example: update with secure defaults for sshd_config and ssh_config
7 years ago
ek9
d6e48f2b43
rebase based on latest update
7 years ago
Javier Bértoli
2db9253c45
Merge pull request #82 from pepoluan/allow_list_or_string
Allow list or string for some option, and setting of ConfigBanner
8 years ago
Javier Bértoli
893b96d023
Merge pull request #83 from llua/redhat
setup sftp correctly on RedHat-like machines
8 years ago
Eric Cook
f4ea96f9c1
setup sftp correctly on RedHat-like machines
8 years ago
Pandu E Poluan
18e1866ac5
Update pillar.example
`pillar.example` now contains information on how to use the
'string-or-list' feature for some options.
Also an explanation on the new `ConfigBanner` option.
8 years ago
Pandu E Poluan
773d9ae092
Apply string-or-list processing to ssh_config
Now ssh_config also accepts string-or-list options, for serveral
keywords.
8 years ago
Pandu E Poluan
30648d115e
Add macro to handle string or list
Added a macro to handle multivalue options entered in either string
format or list format (with auto joiner).
8 years ago
Brian Jackson
b9689cedff
Merge pull request #79 from leansalt/server-service-control
Add ability to control SSH server service status (default: on)
8 years ago
Florian Ermisch
bff3e5d199
Merge pull request #80 from llua/use_pam
do not set UsePAM on OpenBSD
8 years ago
Eric Cook
686fc2c4ee
do not set UsePAM on OpenBSD
Upstream opensshd does not support PAM
8 years ago
Forrest
086937b84f
Merge pull request #76 from freach/master
openssh.auth will produce invalid SLS definition if sshd_config configs are missing
8 years ago
Simon Pirschel
1b69ecab2c
fix issue with stripping new line will result in invalid SLS definition if AuthorizedKeysFile is missing in sshd_config
8 years ago
Forrest
0c06e247d5
Merge pull request #75 from freach/master
sshd won't start if AddressFamily option is specified
8 years ago
Simon Pirschel
2a1b8fbc66
fix issue sshd won't start if AddressFamily is specified, because it must be defined before ListenAddress
8 years ago
Forrest
ec663a6f5e
Merge pull request #51 from mathieupotier/master
Put ssh keys on configured path in sshd_config (AuthorizedKeysFile)
8 years ago
Forrest
263575e57e
Merge pull request #74 from llua/arch_sftp
fix Subsystem directive on archlinux
8 years ago
Eric Cook
51fd8b1391
fix Subsystem directive on archlinux
8 years ago
Forrest
8c1d02f249
Merge pull request #73 from omltorg/updated_archlinux_pkg_name
Update name of package containing dig on ArchLinux
8 years ago
omltorg
de66dbee97
Update name of package containing dig on ArchLinux
8 years ago
Forrest
8d1e730907
Merge pull request #72 from kyrias/AuthKeysCmd
Add AuthorizedKeysCommand support
8 years ago
Johannes Löthberg
a74d859992
Add AuthorizedKeysCommand to pillar.example
Signed-off-by: Johannes Löthberg <johannes@kyriasis.com>
8 years ago
Johannes Löthberg
02b52fa7cf
Add AuthorizedKeysCommand support
Signed-off-by: Johannes Löthberg <johannes@kyriasis.com>
8 years ago
Forrest
329a762e01
Merge pull request #71 from BT-dschleich/patch-1
Fix mine function example in README.rst
8 years ago
Dominik Schleich
7113243334
Fix mine function example in README.rst
like it was already done in the pillar.example in this PR https://github.com/saltstack-formulas/openssh-formula/pull/36 to avoid confusions.
8 years ago
Mathieu POTIER
760a2ad277
fix the path to authkeys
Allow user to specify aliased path (with %u)
8 years ago
Mathieu POTIER
4c814843f8
Merge remote-tracking branch 'refs/remotes/saltstack-formulas/master'
8 years ago
Forrest
5e979f3843
Merge pull request #69 from pepoluan/pepoluan-moduli_pull
Allow moduli to be pulled as file
8 years ago
Pandu E Poluan
11ba2acea7
Give information on using moduli_source
Give additional comments to inform that moduli can also be provided via a file, using the moduli_source key.
8 years ago
Pandu E Poluan
e6603ae62a
Allow moduli to be pulled as file
Added Jinja logic to allow the option to pull the moduli from an online source.
8 years ago