|
99 | 99 | }
|
100 | 100 |
|
101 | 101 | apache::vhost { "puppet-${certname}":
|
102 |
| - port => $puppet_passenger_port, |
103 |
| - priority => '40', |
104 |
| - docroot => $puppet_docroot, |
105 |
| - serveradmin => $apache_serveradmin, |
106 |
| - servername => $certname, |
107 |
| - ssl => true, |
108 |
| - ssl_cert => "${puppet_ssldir}/certs/${certname}.pem", |
109 |
| - ssl_key => "${puppet_ssldir}/private_keys/${certname}.pem", |
110 |
| - ssl_chain => "${puppet_ssldir}/ca/ca_crt.pem", |
111 |
| - ssl_ca => "${puppet_ssldir}/ca/ca_crt.pem", |
112 |
| - ssl_crl => "${puppet_ssldir}/ca/ca_crl.pem", |
113 |
| - rack_base_uris => '/', |
114 |
| - custom_fragment => template('puppet/apache_custom_fragment.erb'), |
115 |
| - require => [ File['/etc/puppet/rack/config.ru'], File[$puppet_conf] ], |
| 102 | + port => $puppet_passenger_port, |
| 103 | + priority => '40', |
| 104 | + docroot => $puppet_docroot, |
| 105 | + serveradmin => $apache_serveradmin, |
| 106 | + servername => $certname, |
| 107 | + ssl => true, |
| 108 | + ssl_cert => "${puppet_ssldir}/certs/${certname}.pem", |
| 109 | + ssl_key => "${puppet_ssldir}/private_keys/${certname}.pem", |
| 110 | + ssl_chain => "${puppet_ssldir}/ca/ca_crt.pem", |
| 111 | + ssl_ca => "${puppet_ssldir}/ca/ca_crt.pem", |
| 112 | + ssl_crl => "${puppet_ssldir}/ca/ca_crl.pem", |
| 113 | + ssl_protocol => '-ALL +SSLv3 +TLSv1', |
| 114 | + ssl_cipher => 'ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:-SSLv2:-EXP', |
| 115 | + ssl_verify_client => 'optional', |
| 116 | + ssl_verify_depth => '1', |
| 117 | + ssl_options => ['+StdEnvVars', '+ExportCertData'], |
| 118 | + rack_base_uris => '/', |
| 119 | + directories => [ |
| 120 | + { |
| 121 | + path => $puppet_docroot, |
| 122 | + }, |
| 123 | + { |
| 124 | + path => '/etc/puppet/rack', |
| 125 | + options => 'None', |
| 126 | + }, |
| 127 | + ], |
| 128 | + require => [ File['/etc/puppet/rack/config.ru'], File[$puppet_conf] ], |
116 | 129 | }
|
117 | 130 |
|
118 | 131 | #Hack to add extra passenger configurations for puppetmaster
|
|
0 commit comments