From 300de9e57bed95b4e9b1e889598dcbfb215f336a Mon Sep 17 00:00:00 2001 From: Ossi Salmi Date: Mon, 17 Jun 2013 23:15:18 +0300 Subject: [PATCH] selinux: Added parameter client_users for selinux::setroubleshoot --- selinux/manifests/init.pp | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/selinux/manifests/init.pp b/selinux/manifests/init.pp index a8cd734..4e06339 100644 --- a/selinux/manifests/init.pp +++ b/selinux/manifests/init.pp @@ -62,16 +62,21 @@ class selinux { # # === Parameters # +# $client_users: +# Array of users allowed to access the setroubleshoot server. +# Defaults to ["*"]. +# # $mailto: # Array of email addresses where to send SELinux alerts. # Disabled by default. # -class selinux::setroubleshoot($mailto=undef) { +class selinux::setroubleshoot($client_users=["*"], $mailto=undef) { if $::selinux == "true" { package { "setroubleshoot": ensure => installed, } + if $::operatingsystem in ["CentOS","RedHat"] and $::operatingsystemrelease =~ /^[1-5]\./ { service { "setroubleshoot": ensure => running, @@ -80,6 +85,15 @@ class selinux::setroubleshoot($mailto=undef) { require => Package["setroubleshoot"], } } + + $client_users_real = inline_template("<%= @client_users.join(',') %>") + augeas { "set-setroubleshoot-client_users": + changes => "set access/client_users '${client_users_real}'", + incl => "/etc/setroubleshoot/setroubleshoot.conf", + lens => "Puppet.lns", + require => Package["setroubleshoot"], + } + if $mailto { if !$mail_server { $mail_server = "127.0.0.1"