aboutsummaryrefslogtreecommitdiff
path: root/manifests/classes/postfix-tlspolicy.pp
blob: 494f257c31026e49b80619b790d3a780f69e9f18 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
#
# == Class: postfix::tlspolicy
#
# Manages Postfix TLS policy by merging policy snippets shipped:
# - in the module's files/tls_policy.d/ or puppet:///files/etc/postfix/tls_policy.d
#   (the latter takes precedence if present); site-postfix module is supported
#   as well, see the source argument of file {"$postfix_tlspolicy_snippets_dir"
#   bellow for details.
# - via postfix::tlspolicy_snippet defines
#
# Parameters:
# - $postfix_tls_fingerprint_digest (defaults to sha1)
#
# Example usage:
# 
#   node "toto.example.com" {
#     $postfix_manage_tls_policy = yes
#     include postfix
#   }
#
class postfix::tlspolicy {

  # Default value for parameters
  case $postfix_tls_fingerprint_digest {
    "": { $postfix_tls_fingerprint_digest = 'sha1' }
  }

  include common::moduledir
  module_dir{'postfix/tls_policy': }

  $postfix_tlspolicy_dir          = "${common::moduledir::module_dir_path}/postfix/tls_policy"
  $postfix_tlspolicy_snippets_dir = "${postfix_tlspolicy_dir}/tls_policy.d"
  $postfix_merged_tlspolicy       = "${postfix_tlspolicy_dir}/merged_tls_policy"

  file {"$postfix_tlspolicy_snippets_dir":
    ensure  => 'directory',
    owner   => 'root',
    group   => '0',
    mode    => '700',
    source  => [
                "puppet:///modules/site-postfix/${fqdn}/tls_policy.d",
                "puppet:///modules/site-postfix/tls_policy.d",
                "puppet:///files/etc/postfix/tls_policy.d",
                "puppet:///modules/postfix/tls_policy.d",
               ],
    recurse => true,
    purge   => false,
  }

  concatenated_file { "$postfix_merged_tlspolicy":
    dir     => "${postfix_tlspolicy_snippets_dir}",
    require => File["$postfix_tlspolicy_snippets_dir"],
  }

  postfix::hash { '/etc/postfix/tls_policy':
    source    => "$postfix_merged_tlspolicy",
    subscribe => File["$postfix_merged_tlspolicy"],
  }

  postfix::config {
    'smtp_tls_fingerprint_digest': value => "$postfix_tls_fingerprint_digest";
  }

  postfix::config { 'smtp_tls_policy_maps':
    value   => 'hash:/etc/postfix/tls_policy',
    require => [
                Postfix::Hash['/etc/postfix/tls_policy'],
                Postfix::Config['smtp_tls_fingerprint_digest'],
               ],
  }

}