| Commit message (Collapse) | Author | Age | Files | Lines | |
|---|---|---|---|---|---|
| * | Allow NM-controlled DNS if intended | Patrick Uiterwijk | 2017-08-21 | 1 | -1/+3 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | move this to a dep instead of including it | Kevin Fenzi | 2017-08-19 | 1 | -3/+0 |
| | | |||||
| * | Turns out it was just missing a name= | Patrick Uiterwijk | 2017-08-16 | 1 | -1/+2 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Turns out name: is incompatible with include_role | Patrick Uiterwijk | 2017-08-16 | 1 | -2/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Move SSH setup to its own role | Patrick Uiterwijk | 2017-08-16 | 2 | -161/+3 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Revert "bypass sshd restart for nowg" | Patrick Uiterwijk | 2017-08-15 | 1 | -1/+1 |
| | | | | | This reverts commit ecb03a1093dd4ad6e5e9e0ac5c3a20eeb1ac4ae3. | ||||
| * | bypass sshd restart for nowg | Patrick Uiterwijk | 2017-08-15 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Lets just call out to date... | Patrick Uiterwijk | 2017-08-15 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Add sshd_cert tag | Patrick Uiterwijk | 2017-08-15 | 1 | -0/+10 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Or no quoting | Patrick Uiterwijk | 2017-08-04 | 1 | -2/+2 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Quote this too. Quote all the things | Patrick Uiterwijk | 2017-08-04 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Fix EPARSE | Patrick Uiterwijk | 2017-08-04 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Deploy sender_access file | Patrick Uiterwijk | 2017-08-04 | 1 | -0/+17 |
| | | | | | Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org> | ||||
| * | when != hen | Patrick Uiterwijk | 2017-07-14 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Teach ansible about the enc900 interface on s390 | Patrick Uiterwijk | 2017-07-14 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | oops, == here not is | Kevin Fenzi | 2017-05-15 | 1 | -4/+4 |
| | | |||||
| * | clean up iptables in base to not apply to cloud compute/master, osbs or os | Kevin Fenzi | 2017-05-15 | 1 | -2/+4 |
| | | |||||
| * | comment in rsyslog-audit module in base | Kevin Fenzi | 2017-05-04 | 1 | -20/+23 |
| | | |||||
| * | initial selinux module work for rsyslog to read audit | Kevin Fenzi | 2017-05-04 | 1 | -0/+21 |
| | | |||||
| * | Revert "ansible tells me not to use {s in when, lets see if this works" | Kevin Fenzi | 2017-04-20 | 1 | -1/+1 |
| | | | | | This reverts commit 9b77ca729b3d8ea304d99e795c9aae77006c57a5. | ||||
| * | ansible tells me not to use {s in when, lets see if this works | Kevin Fenzi | 2017-04-20 | 1 | -1/+1 |
| | | |||||
| * | change state=running to start=started as the old one is going away in ↵ | Kevin Fenzi | 2017-04-13 | 2 | -2/+2 |
| | | | | | ansible 2.7 | ||||
| * | Production key is generated | Patrick Uiterwijk | 2017-04-09 | 1 | -11/+2 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Revert "Make explicitly invalid" | Patrick Uiterwijk | 2017-04-09 | 1 | -1/+1 |
| | | | | | This reverts commit b91d69d1ede9d66a7a24d7fe555d33c9ca4d7574. | ||||
| * | Make explicitly invalid | Patrick Uiterwijk | 2017-04-09 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | SSH does not know years | Patrick Uiterwijk | 2017-04-09 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Combine properly | Patrick Uiterwijk | 2017-04-09 | 1 | -2/+2 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Allow setting additional hostnames | Patrick Uiterwijk | 2017-04-09 | 1 | -2/+2 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Use a static dir | Patrick Uiterwijk | 2017-04-09 | 1 | -9/+12 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Fix env tests | Patrick Uiterwijk | 2017-04-09 | 1 | -10/+10 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Add initial SSH certificates | Patrick Uiterwijk | 2017-04-09 | 2 | -0/+117 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | do not apply iptables to any fed-cloud machine now | Kevin Fenzi | 2017-04-07 | 1 | -1/+1 |
| | | |||||
| * | add tag for common scripts | Kevin Fenzi | 2017-03-02 | 1 | -0/+1 |
| | | |||||
| * | we need to add a larger limits for file coverage | Stephen Smoogen | 2017-01-18 | 1 | -1/+14 |
| | | |||||
| * | Fix missing ) | Kevin Fenzi | 2016-12-05 | 1 | -1/+1 |
| | | |||||
| * | Simplify this conditional for iptables. | Kevin Fenzi | 2016-12-05 | 1 | -1/+1 |
| | | |||||
| * | Exclude the osbs hosts from our default iptables template as they have their ↵ | Kevin Fenzi | 2016-12-05 | 1 | -1/+1 |
| | | | | | own more complex one. | ||||
| * | policycoreutils-python is what we want for semanage on rhel | Kevin Fenzi | 2016-11-30 | 1 | -1/+1 |
| | | |||||
| * | adding check for non-standard ssh and semanage adjustment if found | Tim Flink | 2016-11-30 | 1 | -0/+38 |
| | | |||||
| * | Seems IPA masters need a different krb5 conf | Patrick Uiterwijk | 2016-11-23 | 1 | -0/+9 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | In ansible 2.2 always_run is depreciated. Switch to check_mode. | Kevin Fenzi | 2016-11-01 | 2 | -3/+3 |
| | | |||||
| * | Allow specifying additionally needed host keytabs | Patrick Uiterwijk | 2016-10-27 | 1 | -0/+26 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Move keytab stuff into the base role | Patrick Uiterwijk | 2016-10-27 | 2 | -0/+107 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Create role for host keytab to test before putting in base | Patrick Uiterwijk | 2016-10-27 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Put krb5.conf in base role | Patrick Uiterwijk | 2016-10-13 | 1 | -0/+7 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | tweak base role interfaces for docker networks | Kevin Fenzi | 2016-10-10 | 1 | -1/+1 |
| | | |||||
| * | Install complete.crt into .crt | Patrick Uiterwijk | 2016-09-27 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | Install gateway cert with intermediate cert | Patrick Uiterwijk | 2016-09-27 | 1 | -1/+1 |
| | | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | ||||
| * | push the tls change out to the smtp-mm boxes | Stephen Smoogen | 2016-09-27 | 1 | -3/+3 |
| | | |||||
| * | Fix the order of this handler | Kevin Fenzi | 2016-09-27 | 1 | -1/+1 |
| | | |||||
