[Puppet Users] Security: Potential exposure of CA key under puppetserver

2015-09-29 Thread Eric Sorenson
We've identified and are fixing a condition in puppet where the auto-generated CA private key is created with too-leinent permissions. We feel the exposure is pretty limited (it would require a local user account on the CA system, to discover and copy/modify the CA key before additional puppet com

[Puppet Users] mysql service class does not start stopped service

2015-09-29 Thread Tim Dunphy
Hey puppeters, Got a question about a service class for a mysql module that I wrote. I've seen that this class: class mysql::service { if $osfamily == "RedHat" and $operatingsystemmajrelease == 7 { service {"mysql": ensure => running, hasstatus => true,

[Puppet Users] Re: Slow user resource-type when host is attached to LDAP directory

2015-09-29 Thread Alan Chalmers
Nope. we have forcelocal true already. On Tuesday, 29 September 2015 20:14:38 UTC+10, Stefan Heijmans wrote: > > There is a user resource attribute; > forcelocal [1] > Forces the management of local accounts when accounts are also being > managed by some other NSS > > Doens't this help? > >

Re: [Puppet Users] Re: Forge ACL Module 1.1.1 on Windows 7 x64 SP1

2015-09-29 Thread jmp242
Sure, that's perhaps misleading a little - our internal custom puppet module is called yum as it was created for EL6 first. When we got a package manager on Windows, i.e. chocolatey, it seemed to make sense to put it in the Windows section of the yum module. By that I mean we have a switch on k

Re: [Puppet Users] Slow user resource-type when host is attached to LDAP directory

2015-09-29 Thread Dan White
Me too, please “Sometimes I think the surest sign that intelligent life exists elsewhere in the universe is that none of it has tried to contact us.” (Bill Waterson: Calvin & Hobbes) On Sep 29, 2015, at 05:53 AM, Alan Chalmers wrote: Josh, Did you ever get a resolution for this? thanks al

Re: [Puppet Users] Puppetdb garbage collection failing

2015-09-29 Thread Wyatt Alt
On 9/29/15 12:20 AM, Matt Jarvis wrote: count | name ---+- 1 | macaddress_qvb34470225_cd 1 | mtu_qbr2fb476b3_ff 1 | speed_qvbfa2ec4e3_15 1 | macaddress_qvo547572f9_14 1 | speed_qvo2e200191_c0 1 | mtu_qbr5ea

[Puppet Users] Dependent Ruby Gems - One run or Two

2015-09-29 Thread Fraser Goffin
Puppet v 4.2.x Platform: Windows I'm using the Atlassian sonatype_nexus Puppet module. It allows you to configure Nexus via its RESTful API using a number of abstractions from the module. However, ... there is a requirement for a few additional Ruby gems to be installed, the key one being a res

[Puppet Users] Official Documentation for Puppet 3.8 Open Source in epub or mobi format?

2015-09-29 Thread tobias . koeck
Is there the official documentation for Puppet 3.8 Open Source in epub or mobi format? I have found an older PDF file but no documentation for newer puppet versions. -- You received this message because you are subscribed to the Google Groups "Puppet Users" group. To unsubscribe from this gro

[Puppet Users] Re: should create_resources honor schedule metaparameter?

2015-09-29 Thread jcbollinger
On Monday, September 28, 2015 at 10:17:31 PM UTC-5, Tom Downes wrote: > > I have a defined resource that I instantiate through create_resources and > a set of defaults that trace back to hiera: > > create_resources("apache::vhost", $full_apache_hash, $http_defaults) > > > http_defaults: > > sc

[Puppet Users] Re: Slow user resource-type when host is attached to LDAP directory

2015-09-29 Thread Stefan Heijmans
There is a user resource attribute; forcelocal [1] Forces the management of local accounts when accounts are also being managed by some other NSS Doens't this help? [1] https://docs.puppetlabs.com/references/latest/type.html#user-attribute-forcelocal On Tuesday, September 29, 2015 at 11:5

[Puppet Users] Re: Slow user resource-type when host is attached to LDAP directory

2015-09-29 Thread Alan Chalmers
Josh, Did you ever get a resolution for this? thanks alan On Wednesday, 20 March 2013 04:34:23 UTC+11, Josh wrote: > > The majority of our servers are attached to large LDAP directories. > However, there are also cases when we need to define local service > accounts for whatever reason. We

[Puppet Users] Re: Puppet Strings Error

2015-09-29 Thread Dan
Hi Ian, Ok no problem with the lack of love for Windows ;-) If you spot anything and want me to test please let me know. Thanks Dan On Monday, 28 September 2015 17:50:16 UTC+1, Ian Kronquist wrote: > > Hi Dan, > Thanks for testing out Strings on Windows! We really haven't given Strings > eno

Re: [Puppet Users] Puppetdb garbage collection failing

2015-09-29 Thread Matt Jarvis
count | name ---+- 1 | macaddress_qvb34470225_cd 1 | mtu_qbr2fb476b3_ff 1 | speed_qvbfa2ec4e3_15 1 | macaddress_qvo547572f9_14 1 | speed_qvo2e200191_c0 1 | mtu_qb