Add bridge and server config files in
This commit is contained in:
parent
5c6ba16f97
commit
e0116a88b9
3 changed files with 83 additions and 0 deletions
29
files/sign/bridge.conf.j2
Normal file
29
files/sign/bridge.conf.j2
Normal file
|
@ -0,0 +1,29 @@
|
||||||
|
# This is a configuration for the sigul bridge.
|
||||||
|
|
||||||
|
[bridge]
|
||||||
|
# Nickname of the bridge's certificate in the NSS database specified below
|
||||||
|
bridge-cert-nickname: sign-bridge1 - Fedora Project
|
||||||
|
# Port on which the bridge expects client connections
|
||||||
|
client-listen-port: 44334
|
||||||
|
# Port on which the bridge expects server connections
|
||||||
|
server-listen-port: 44333
|
||||||
|
# A Fedora account system group required for access to the signing server. If
|
||||||
|
# empty, no Fedora account check is done.
|
||||||
|
required-fas-group: signers
|
||||||
|
# User name and password for an account on the Fedora account system that can
|
||||||
|
# be used to verify group memberships
|
||||||
|
fas-user-name: {{ fedoraDummyUser }}
|
||||||
|
fas-password: {{ fedoraDummyUserPassword }}
|
||||||
|
|
||||||
|
[daemon]
|
||||||
|
# The user to run as
|
||||||
|
unix-user: sigul
|
||||||
|
# The group to run as
|
||||||
|
unix-group: sigul
|
||||||
|
|
||||||
|
[nss]
|
||||||
|
# Path to a directory containing a NSS database
|
||||||
|
nss-dir: /var/lib/sigul
|
||||||
|
# Password for accessing the NSS database. If not specified, the bridge will
|
||||||
|
# ask on startup
|
||||||
|
; nss-password:
|
46
files/sign/server.conf
Normal file
46
files/sign/server.conf
Normal file
|
@ -0,0 +1,46 @@
|
||||||
|
# This is a configuration for the sigul server.
|
||||||
|
|
||||||
|
[server]
|
||||||
|
# Host name of the publically acessible bridge to clients
|
||||||
|
bridge-hostname: sign-bridge1
|
||||||
|
# Port on which the bridge expects server connections
|
||||||
|
bridge-port: 44333
|
||||||
|
# Maximum accepted size of payload stored on disk
|
||||||
|
max-file-payload-size: 2073741824
|
||||||
|
# Maximum accepted size of payload stored in server's memory
|
||||||
|
max-memory-payload-size: 1048576
|
||||||
|
# Nickname of the server's certificate in the NSS database specified below
|
||||||
|
server-cert-nickname: sign-vault1 - Fedora Project
|
||||||
|
|
||||||
|
[database]
|
||||||
|
# Path to a directory containing a SQLite database
|
||||||
|
;database-path: /var/lib/sigul
|
||||||
|
|
||||||
|
[gnupg]
|
||||||
|
# Path to a directory containing GPG configuration and keyrings
|
||||||
|
gnupg-home: /var/lib/sigul/gnupg
|
||||||
|
# Default primary key type for newly created keys
|
||||||
|
gnupg-key-type: RSA
|
||||||
|
# Default primary key length for newly created keys
|
||||||
|
gnupg-key-length: 4096
|
||||||
|
# Default subkey type for newly created keys, empty for no subkey
|
||||||
|
gnupg-subkey-type:
|
||||||
|
# Default subkey length for newly created keys if gnupg-subkey-type is not empty
|
||||||
|
; gnupg-subkey-length: 2048
|
||||||
|
# Default key usage flags for newly created keys
|
||||||
|
gnupg-key-usage: encrypt, sign
|
||||||
|
# Length of key passphrases used for newsly created keys
|
||||||
|
passphrase-length: 64
|
||||||
|
|
||||||
|
[daemon]
|
||||||
|
# The user to run as
|
||||||
|
unix-user: sigul
|
||||||
|
# The group to run as
|
||||||
|
unix-group: sigul
|
||||||
|
|
||||||
|
[nss]
|
||||||
|
# Path to a directory containing a NSS database
|
||||||
|
nss-dir: /var/lib/sigul
|
||||||
|
# Password for accessing the NSS database. If not specified, the server will
|
||||||
|
# ask on startup
|
||||||
|
; nss-password is not specified by default
|
|
@ -9,6 +9,14 @@
|
||||||
tags:
|
tags:
|
||||||
- packages
|
- packages
|
||||||
|
|
||||||
|
- name: setup /etc/sigul/client.conf file
|
||||||
|
action: template src=$files/sign/client.conf.j2 dest=/etc/sigul/client.conf owner=root group=sigul mode=640
|
||||||
|
tags:
|
||||||
|
- config
|
||||||
|
|
||||||
|
- name: setup /etc/sigul/server.conf file
|
||||||
|
action: copy src=$files/sign/server.conf dest=/etc/sigul/server.conf owner=root group=sigul mode=640
|
||||||
|
|
||||||
- name: ntp steptickers
|
- name: ntp steptickers
|
||||||
action: copy src=$files/common/step-tickers dest=/etc/ntp/step-tickers
|
action: copy src=$files/common/step-tickers dest=/etc/ntp/step-tickers
|
||||||
|
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue