| Commit message (Collapse) | Author | Age | Files | Lines | |
|---|---|---|---|---|---|
| * | Separate running the SSH keys script from the mgagit script (mga#34826) | Dan Fandrich | 2026-01-07 | 1 | -1/+1 |
| | | | | | | | | | | The mgagit script was previously run after the SSH keys script, but only if an SSH key was updated. That meant that any group changes were not reflected until after someone changed an SSH key. Decouple the running of the two scripts since they are not (completely) dependent on each other. | ||||
| * | Use @ when accessing variables in templates | Dan Fandrich | 2024-11-20 | 1 | -4/+4 |
| | | | | | | | | | Access without the @ symbol is the older method and is discouraged. This take leaves alone accesses of variables that are defined within the template, which don't seem to allow an @. This is the second batch of files. | ||||
| * | Remove conditionals for releases older than Mageia 6 | Dan Fandrich | 2024-10-15 | 1 | -15/+0 |
| | | | | | | This eliminates a bunch of conditionals, simplifying the configuration. We no longer have any servers running on a release older than this. | ||||
| * | Revert "Use @ when accessing variables in templates" | Dan Fandrich | 2024-10-04 | 2 | -6/+6 |
| | | | | | | | Variables defined within a template can't be accessed with @. This change needs to be reworked to eliminate those cases. This reverts commits 2c7da665 and ae197622. | ||||
| * | Use @ when accessing variables in templates | Dan Fandrich | 2024-10-04 | 2 | -6/+6 |
| | | | | | Access without the @ symbol is the older method and is discouraged. | ||||
| * | Remove some extra quote characters accidentally submitted | Dan Fandrich | 2023-12-27 | 1 | -3/+1 |
| | | |||||
| * | Port ldap-sshkey2file.py to Python 3 | Dan Fandrich | 2023-12-27 | 2 | -96/+91 |
| | | | | | It now also passes pytype and (mostly) flake8 checks. | ||||
| * | this is python2 code | Thomas Backlund | 2021-11-28 | 1 | -1/+1 |
| | | |||||
| * | flip package names on require too | Thomas Backlund | 2019-09-18 | 1 | -2/+2 |
| | | |||||
| * | flip package names | Thomas Backlund | 2019-09-18 | 1 | -2/+2 |
| | | |||||
| * | fix up versioncmp issues | Thomas Backlund | 2019-09-16 | 1 | -2/+5 |
| | | |||||
| * | openssh: fix up python2-ldap deps for mga7 | Thomas Backlund | 2019-09-16 | 1 | -0/+4 |
| | | |||||
| * | fix up openssh python2-ldap | Thomas Backlund | 2019-09-16 | 1 | -2/+2 |
| | | |||||
| * | adjust openssh deps for mga7 | Thomas Backlund | 2019-09-16 | 1 | -0/+4 |
| | | |||||
| * | Disable ChallengeResponseAuthentication | Pascal Terjan | 2018-03-04 | 1 | -1/+1 |
| | | |||||
| * | sshd: disable UsePAM | Thomas Backlund | 2018-03-04 | 1 | -1/+1 |
| | | |||||
| * | Stop using ssh_host_key on Mageia 6 | Pascal Terjan | 2017-09-24 | 1 | -0/+2 |
| | | |||||
| * | Drop deprecated sshd option | Pascal Terjan | 2017-09-24 | 1 | -0/+2 |
| | | |||||
| * | Make Mageia 6 fix more widely avaialable | Pascal Terjan | 2017-09-24 | 1 | -6/+6 |
| | | |||||
| * | Workaround lack of mga6 support in our configs | Pascal Terjan | 2017-09-24 | 2 | -0/+10 |
| | | |||||
| * | ldap-sshkey2file.py: add dry-run and verbose mode | Olivier Blin | 2017-02-23 | 1 | -0/+16 |
| | | |||||
| * | ldap-sshkey2file.py: use argparse for options parsing and usage | Olivier Blin | 2017-02-23 | 1 | -16/+15 |
| | | |||||
| * | ldap-sshkey2file.py: reorder code in write_keys to prepare adding a dry-run mode | Olivier Blin | 2017-02-23 | 1 | -29/+29 |
| | | |||||
| * | ldap-sshkey2file.py: fix path of authorized_keys in usage | Olivier Blin | 2017-02-23 | 1 | -1/+1 |
| | | |||||
| * | Fix ldap-sshkey2file so it doesn't crash when a user has no uidNumber | Dan Fandrich | 2017-02-23 | 1 | -3/+3 |
| | | | | | | This shouldn't happen in normal operation, but can happen when binding to a DN who doesn't have access to that attribute. | ||||
| * | Allow mga-unrestricted_shell_access group login on duvel | Olivier Blin | 2017-02-21 | 1 | -1/+1 |
| | | | | | Also-by: Dan Fandrich <dan@coneharvesters.com> | ||||
| * | Remove unnecessary AllowGroups sshd restriction on rabbit | Olivier Blin | 2017-02-21 | 1 | -4/+0 |
| | | | | | | | | | This is already covered by pam.d/system-auth, which only allows local users and authorized access classes. Otherwise, login fails: sshd[1234]: fatal: Access denied for user XXX by PAM account configuration [preauth] | ||||
| * | Disable password for ssh on all machines | Pascal Terjan | 2016-10-13 | 1 | -1/+1 |
| | | |||||
| * | Allow iurt to ssh to rabbit | Pascal Terjan | 2016-10-13 | 1 | -1/+1 |
| | | |||||
| * | Restrict ssh access on rabbit | Pascal Terjan | 2016-10-13 | 1 | -0/+4 |
| | | |||||
| * | openssh: Fix writing ssh public keys, with new ldap secret location | Olivier Blin | 2016-02-21 | 2 | -5/+40 |
| | | | | | ldap secret is now stored in the bindpw field of /etc/nslcd.conf | ||||
| * | Allow members of mga-sysadmin to log in via ssh | Dan Fandrich | 2016-02-19 | 1 | -1/+1 |
| | | | | | | This only works on hosts where users' ssh keys are copied, namely those including openssh::ssh_keys_from_ldap | ||||
| * | openssh: do not force command for git user | Olivier Blin | 2016-02-07 | 1 | -1/+2 |
| | | | | | | The "gitolite <username>" is already set in /var/lib/git/.ssh/authorized_keys, and we do not want to override it. | ||||
| * | openssh: fix forcing sv_membersh command | Olivier Blin | 2016-02-07 | 1 | -1/+1 |
| | | | | | | | | | | | The following rule did not work as intended: Match User !schedbot User !root This one does (with a leading wildcard): Match User *,!schedbot,!root See http://superuser.com/questions/952235/why-arent-my-negative-matches-working | ||||
| * | Force sv_membersh.pl in ssh on duvel | Pascal Terjan | 2016-02-07 | 1 | -0/+4 |
| | | | | | | That way we don't need to have it as default shell for everyone on the machine It should probably not hardcode duvel though | ||||
| * | variable enclosing fixes | Thomas Backlund | 2015-10-20 | 1 | -1/+1 |
| | | |||||
| * | openssh: Ensure ownership is set correctly on authorized_keys | Colin Guthrie | 2015-02-06 | 1 | -0/+5 |
| | | | | | | | This was highlighted by a problem encountered by Nicolas Salguero. Many thanks for your patience. | ||||
| * | openssh: Fix python copy/paste error. | Colin Guthrie | 2015-02-03 | 1 | -1/+1 |
| | | | | | Introduced in d5148ffbb0514c37893002e4988c5f7f379586bf | ||||
| * | openssh: Also update gitolite config when SSH keys change. | Colin Guthrie | 2015-01-18 | 1 | -1/+1 |
| | | | | | | This should avoid the problems encountered recently with Donald's SSH key update and git access. | ||||
| * | openssh: Return failure when no keys are updated. | Colin Guthrie | 2015-01-18 | 1 | -2/+15 |
| | | | | | We can then use this exit status to run other commands when keys are updated. | ||||
| * | openssh: Only write authorized_keys file when it's different | Colin Guthrie | 2015-01-18 | 1 | -7/+20 |
| | | | | | | This saves disk churn and will eventually allow us to take further action when keys actually change. | ||||
| * | openssh: Use temp file when writing keys from LDAP. | Colin Guthrie | 2015-01-18 | 1 | -7/+12 |
| | | | | | | | | This helps avoid a race condition when the file is not yet written properly when a new SSH connection from that user comes in. This isn't really a problem in practice, but we may as well do it. | ||||
| * | Revert "Temporary hack to work around LDAP server sync problem" | Colin Guthrie | 2014-09-23 | 1 | -6/+0 |
| | | | | | | | This reverts commit cc302084ccf54fb8f067f8dd5d7f7c07ed50b019. Slave LDAP now back cookin' on gas! | ||||
| * | Temporary hack to work around LDAP server sync problem | Colin Guthrie | 2014-09-16 | 1 | -0/+6 |
| | | |||||
| * | Partially revert part of r3378 which wasn't meant to be in the commit :( | Colin Guthrie | 2013-12-05 | 1 | -2/+0 |
| | | |||||
| * | Add mgaonline to the freeze exception pkg regexp | Colin Guthrie | 2013-12-05 | 1 | -0/+2 |
| | | |||||
| * | openssh::ssh_keys_from_ldap: remove unused parameter | Nicolas Vigier | 2013-07-06 | 1 | -1/+1 |
| | | |||||
| * | openssh: switch to standard path for authorized_keys file | Nicolas Vigier | 2013-07-06 | 4 | -53/+1 |
| | | |||||
| * | ldap-sshkey2file.py: export ssh keys to /home directory | Nicolas Vigier | 2013-07-06 | 1 | -5/+14 |
| | | | | | Thanks to Colin for help on this | ||||
| * | More mga-common mga_common remaning | Nicolas Vigier | 2013-06-19 | 1 | -1/+1 |
| | | |||||
