--- Exec[create chained cert /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chain.pem].orig
+++ Exec[create chained cert /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chain.pem]
- unless => /usr/bin/test "$(/bin/cat /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.pem /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chain.pem | sha512sum)" == "$(/bin/cat /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chained.pem | sha512sum)"
- require => Exec[Generate cert syslog__centrallog2002_codfw_wmnet refresh on intermediate ca change]
- subscribe => ['Exec[renew certificate - syslog__centrallog2002_codfw_wmnet]', 'File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chain.pem]', 'File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.pem]']
- command => /bin/cat /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.pem /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chain.pem > /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chained.pem
Cfssl::Cert[syslog__centrallog2002_codfw_wmnet]
- Parameters differences:
--- Cfssl::Cert[syslog__centrallog2002_codfw_wmnet].orig
+++ Cfssl::Cert[syslog__centrallog2002_codfw_wmnet]
- mode => 0740
- hosts => []
- before_services => []
- renew_seconds => 952200
- provide_chain => True
- notify_services => []
- group => root
- label => syslog
- common_name => centrallog2002.codfw.wmnet
- auto_renew => True
- key => {'algo': 'ecdsa', 'size': 256}
- ensure => present
- environment => ['GODEBUG=x509ignoreCN=0']
- names => []
- owner => root
- Class[Rsyslog::Receiver]
- Parameters differences:
--- Class[Rsyslog::Receiver].orig
+++ Class[Rsyslog::Receiver]
- ssl_provider => cfssl
+ ca_file => /etc/ssl/certs/wmf-ca-certificates.crt
- File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.csr]
- Parameters differences:
--- File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.csr].orig
+++ File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.csr]
- mode => 0440
- ensure => file
- group => root
- owner => root
- Systemd::Timer::Job[rsyslog-receiver-remedy]
- Parameters differences:
--- Systemd::Timer::Job[rsyslog-receiver-remedy].orig
+++ Systemd::Timer::Job[rsyslog-receiver-remedy]
@@
- command => /bin/sh -c "timeout 5s openssl s_client -connect localhost:6514 -cert_chain /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chained.pem -cert /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chained.pem -key /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet-key.pem -CAfile /etc/ssl/certs/wmf-ca-certificates.crt -quiet -no_ign_eof </dev/null || systemctl restart rsyslog-receiver"
+ command => /bin/sh -c "timeout 5s openssl s_client -connect localhost:6514 -cert_chain /etc/cfssl/ssl/syslog__rsyslog-receiver/syslog__rsyslog-receiver.chained.pem -cert /etc/cfssl/ssl/syslog__rsyslog-receiver/syslog__rsyslog-receiver.chained.pem -key /etc/cfssl/ssl/syslog__rsyslog-receiver/syslog__rsyslog-receiver-key.pem -CAfile /etc/ssl/certs/wmf-ca-certificates.crt -quiet -no_ign_eof </dev/null || systemctl restart rsyslog-receiver"
- Cfssl::Csr[/etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr]
- Parameters differences:
--- Cfssl::Csr[/etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr].orig
+++ Cfssl::Csr[/etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr]
- common_name => centrallog2002.codfw.wmnet
- hosts => []
- key => {'algo': 'ecdsa', 'size': 256}
- ensure => present
- names => []
- Systemd::Unit[rsyslog-receiver-remedy.service]
- File[/etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr]
- Parameters differences:
--- File[/etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr].orig
+++ File[/etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr]
- mode => 0400
- ensure => file
- group => root
- owner => root
- Content differences:
--- /etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr.orig
+++ /etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr
@@ -1,13 +0,0 @@
-{
- "CN": "centrallog2002.codfw.wmnet",
- "hosts": [
- "centrallog2002.codfw.wmnet"
- ],
- "key": {
- "algo": "ecdsa",
- "size": 256
- },
- "names": [
-
- ]
-}
- Exec[Generate cert syslog__centrallog2002_codfw_wmnet refresh on intermediate ca change]
- Parameters differences:
--- Exec[Generate cert syslog__centrallog2002_codfw_wmnet refresh on intermediate ca change].orig
+++ Exec[Generate cert syslog__centrallog2002_codfw_wmnet refresh on intermediate ca change]
- refreshonly => True
- environment => ['GODEBUG=x509ignoreCN=0']
- subscribe => File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chain.pem]
- command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/centrallog2002.codfw.wmnet.pem -label syslog /etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr | /usr/bin/cfssljson -bare /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet
- Exec[renew certificate - syslog__centrallog2002_codfw_wmnet]
- Parameters differences:
--- Exec[renew certificate - syslog__centrallog2002_codfw_wmnet].orig
+++ Exec[renew certificate - syslog__centrallog2002_codfw_wmnet]
- unless => /usr/bin/openssl x509 -in /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.pem -checkend 952200
- require => Exec[Generate cert syslog__centrallog2002_codfw_wmnet]
- environment => ['GODEBUG=x509ignoreCN=0']
- command => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/centrallog2002.codfw.wmnet.pem -label syslog /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.csr | /usr/bin/cfssljson -bare /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet
- File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chain.pem]
- Parameters differences:
--- File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chain.pem].orig
+++ File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chain.pem]
- mode => 0440
- source => puppet:///modules/profile/pki/intermediates/syslog-cert.pem
- ensure => file
- group => root
- owner => root
- File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet-key.pem]
- Parameters differences:
--- File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet-key.pem].orig
+++ File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet-key.pem]
- mode => 0440
- backup => False
- ensure => file
- group => root
- show_diff => False
- owner => root
- Exec[Generate cert syslog__centrallog2002_codfw_wmnet refresh]
- Parameters differences:
--- Exec[Generate cert syslog__centrallog2002_codfw_wmnet refresh].orig
+++ Exec[Generate cert syslog__centrallog2002_codfw_wmnet refresh]
- refreshonly => True
- environment => ['GODEBUG=x509ignoreCN=0']
- subscribe => File[/etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr]
- command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/centrallog2002.codfw.wmnet.pem -label syslog /etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr | /usr/bin/cfssljson -bare /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet
- File[/lib/systemd/system/rsyslog-receiver-remedy.service]
- Content differences:
--- /lib/systemd/system/rsyslog-receiver-remedy.service.orig
+++ /lib/systemd/system/rsyslog-receiver-remedy.service
@@ -5,4 +5,4 @@
[Service]
Type=oneshot
User=root
-ExecStart=/bin/sh -c "timeout 5s openssl s_client -connect localhost:6514 -cert_chain /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chained.pem -cert /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.chained.pem -key /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet-key.pem -CAfile /etc/ssl/certs/wmf-ca-certificates.crt -quiet -no_ign_eof </dev/null || systemctl restart rsyslog-receiver"
+ExecStart=/bin/sh -c "timeout 5s openssl s_client -connect localhost:6514 -cert_chain /etc/cfssl/ssl/syslog__rsyslog-receiver/syslog__rsyslog-receiver.chained.pem -cert /etc/cfssl/ssl/syslog__rsyslog-receiver/syslog__rsyslog-receiver.chained.pem -key /etc/cfssl/ssl/syslog__rsyslog-receiver/syslog__rsyslog-receiver-key.pem -CAfile /etc/ssl/certs/wmf-ca-certificates.crt -quiet -no_ign_eof </dev/null || systemctl restart rsyslog-receiver"
- File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet]
- Parameters differences:
--- File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet].orig
+++ File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet]
- mode => 0740
- recurse => True
- ensure => directory
- group => root
- owner => root
- Class[Toil::Rsyslog_receiver_remedy]
- Parameters differences:
--- Class[Toil::Rsyslog_receiver_remedy].orig
+++ Class[Toil::Rsyslog_receiver_remedy]
- ssl_provider => cfssl
+ ca_file => /etc/ssl/certs/wmf-ca-certificates.crt
+ cert_file => /etc/cfssl/ssl/syslog__rsyslog-receiver/syslog__rsyslog-receiver.chained.pem
+ key_file => /etc/cfssl/ssl/syslog__rsyslog-receiver/syslog__rsyslog-receiver-key.pem
- Exec[Generate cert syslog__centrallog2002_codfw_wmnet]
- Parameters differences:
--- Exec[Generate cert syslog__centrallog2002_codfw_wmnet].orig
+++ Exec[Generate cert syslog__centrallog2002_codfw_wmnet]
- unless => /usr/bin/test "$(/usr/bin/openssl x509 -in /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.pem -noout -pubkey 2>&1)" == "$(/usr/bin/openssl pkey -pubout -in /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet-key.pem 2>&1)"
- require => Cfssl::Csr[/etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr]
- environment => ['GODEBUG=x509ignoreCN=0']
- command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/centrallog2002.codfw.wmnet.pem -label syslog /etc/cfssl/csr/syslog__centrallog2002_codfw_wmnet.csr | /usr/bin/cfssljson -bare /etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet
- File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.pem]
- Parameters differences:
--- File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.pem].orig
+++ File[/etc/cfssl/ssl/syslog__centrallog2002_codfw_wmnet/syslog__centrallog2002_codfw_wmnet.pem]
- mode => 0440
- ensure => file
- group => root
- owner => root