Closed Bug 879347 Opened 11 years ago Closed 11 years ago

Add a bunch of host keys to puppet

Categories

(Infrastructure & Operations :: RelOps: General, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: dustin, Assigned: dustin)

Details

Attachments

(1 file)

At least github and people.m.o.  Add your other suggestions here!

A missing host key is not a security mechanism.  If a particular user/host should not have access to some other user/host, SSH auth should be preventing that, not the nonexistence of a host key.
Also, all of the puppet masters
Attached patch bug879347.patchSplinter Review
This puts known hosts in the system global file, but *also* in root and builder's ~/.ssh, since ~builder/.ssh/known_hosts is required for mock builds.

I tested the puppetsync crontask, and it still works fine.
Attachment #759258 - Flags: review?(rail)
Attachment #759258 - Flags: review?(rail) → review+
Attachment #759258 - Flags: checked-in+
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → FIXED
Comment on attachment 759258 [details] [diff] [review]
bug879347.patch

I'm curious why people.m.{o,c} was added, since it is blocked flow-wise from all the hosts that I know of in the buildVPN
Not all - I often send puppet patches there for upload to bugzilla.
Component: Server Operations: RelEng → RelOps
Product: mozilla.org → Infrastructure & Operations
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: