|
| 1 | +# yamllint disable rule:indentation rule:line-length |
| 2 | +# Debian-12 |
| 3 | +--- |
| 4 | +values: |
| 5 | + map_jinja: |
| 6 | + sources: |
| 7 | + - Y:G@osarch |
| 8 | + - Y:G@os_family |
| 9 | + - Y:G@os |
| 10 | + - Y:G@osfinger |
| 11 | + - C:SUB@openssh:lookup |
| 12 | + - C:SUB@openssh |
| 13 | + - C:SUB@sshd_config:lookup |
| 14 | + - C:SUB@sshd_config |
| 15 | + - C:SUB@ssh_config:lookup |
| 16 | + - C:SUB@ssh_config |
| 17 | + - Y:G@id |
| 18 | + openssh: |
| 19 | + absent_dsa_keys: false |
| 20 | + absent_ecdsa_keys: false |
| 21 | + absent_ed25519_keys: false |
| 22 | + absent_rsa_keys: false |
| 23 | + auth: |
| 24 | + joe-non-valid-ssh-key: |
| 25 | + - comment: obsolete key - removed |
| 26 | + enc: ssh-rsa |
| 27 | + present: false |
| 28 | + source: salt://ssh_keys/joe.no-valid.pub |
| 29 | + user: joe |
| 30 | + joe-valid-ssh-key-desktop: |
| 31 | + - comment: main key - desktop |
| 32 | + enc: ssh-rsa |
| 33 | + present: true |
| 34 | + source: salt://ssh_keys/joe.desktop.pub |
| 35 | + user: joe |
| 36 | + joe-valid-ssh-key-notebook: |
| 37 | + - comment: main key - notebook |
| 38 | + enc: ssh-rsa |
| 39 | + present: true |
| 40 | + source: salt://ssh_keys/joe.netbook.pub |
| 41 | + user: joe |
| 42 | + auth_map: |
| 43 | + personal_keys: |
| 44 | + source: salt://ssh_keys |
| 45 | + users: |
| 46 | + joe: |
| 47 | + joe.desktop: {} |
| 48 | + joe.netbook: |
| 49 | + options: [] |
| 50 | + joe.no-valid: |
| 51 | + present: false |
| 52 | + banner: /etc/ssh/banner |
| 53 | + banner_src: banner |
| 54 | + banner_string: 'Welcome to example.net! |
| 55 | + ' |
| 56 | + client: openssh-client |
| 57 | + client_version: latest |
| 58 | + dig_pkg: bind9-dnsutils |
| 59 | + dsa: |
| 60 | + private_key: '-----BEGIN DSA PRIVATE KEY----- |
| 61 | +
|
| 62 | + NOT_DEFINED |
| 63 | +
|
| 64 | + -----END DSA PRIVATE KEY----- |
| 65 | + ' |
| 66 | + public_key: 'ssh-dss NOT_DEFINED |
| 67 | + ' |
| 68 | + ecdsa: |
| 69 | + private_key: '-----BEGIN EC PRIVATE KEY----- |
| 70 | +
|
| 71 | + NOT_DEFINED |
| 72 | +
|
| 73 | + -----END EC PRIVATE KEY----- |
| 74 | + ' |
| 75 | + public_key: 'ecdsa-sha2-nistp256 NOT_DEFINED |
| 76 | + ' |
| 77 | + ed25519: |
| 78 | + private_key: '-----BEGIN OPENSSH PRIVATE KEY----- |
| 79 | +
|
| 80 | + NOT_DEFINED |
| 81 | +
|
| 82 | + -----END OPENSSH PRIVATE KEY----- |
| 83 | + ' |
| 84 | + public_key: 'ssh-ed25519 NOT_DEFINED |
| 85 | + ' |
| 86 | + enforce_rsa_size: false |
| 87 | + generate_dsa_keys: false |
| 88 | + generate_ecdsa_keys: false |
| 89 | + generate_ed25519_keys: false |
| 90 | + generate_rsa_keys: false |
| 91 | + generate_rsa_size: 4096 |
| 92 | + host_key_algos: ecdsa,ed25519,rsa |
| 93 | + known_hosts: |
| 94 | + aliases: |
| 95 | + - cname-to-minion.example.org |
| 96 | + - alias.example.org |
| 97 | + hostnames: false |
| 98 | + include_localhost: false |
| 99 | + mine_hostname_function: public_ssh_hostname |
| 100 | + mine_keys_function: public_ssh_host_keys |
| 101 | + omit_ip_address: |
| 102 | + - github.com |
| 103 | + salt_ssh: |
| 104 | + public_ssh_host_keys: |
| 105 | + minion.id: 'ssh-rsa [...] |
| 106 | +
|
| 107 | + ssh-ed25519 [...] |
| 108 | + ' |
| 109 | + public_ssh_host_names: |
| 110 | + minion.id: |
| 111 | + - minion.id |
| 112 | + - alias.of.minion.id |
| 113 | + user: salt-master |
| 114 | + static: |
| 115 | + github.com: ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAq2A7hRGm[...] |
| 116 | + gitlab.com: ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCsj2bN[...] |
| 117 | + target: '*' |
| 118 | + tgt_type: glob |
| 119 | + moduli: '# Time Type Tests Tries Size Generator Modulus |
| 120 | +
|
| 121 | + 20120821045639 2 6 100 2047 2 DD2047CBDBB6F8E919BC63DE885B34D0FD6E3DB2887D8B46FE249886ACED6B46DFCD5553168185FD376122171CD8927E60120FA8D01F01D03E58281FEA9A1ABE97631C828E41815F34FDCDF787419FE13A3137649AA93D2584230DF5F24B5C00C88B7D7DE4367693428C730376F218A53E853B0851BAB7C53C15DA7839CBE1285DB63F6FA45C1BB59FE1C5BB918F0F8459D7EF60ACFF5C0FA0F3FCAD1C5F4CE4416D4F4B36B05CDCEBE4FB879E95847EFBC6449CD190248843BC7EDB145FBFC4EDBB1A3C959298F08F3BA2CFBE231BBE204BE6F906209D28BD4820AB3E7BE96C26AE8A809ADD8D1A5A0B008E9570FA4C4697E116B8119892C604293680B09D63 |
| 122 | +
|
| 123 | + 20120821045830 2 6 100 2047 2 DD2047CBDBB6F8E919BC63DE885B34D0FD6E3DB2887D8B46FE249886ACED6B46DFCD5553168185FD376122171CD8927E60120FA8D01F01D03E58281FEA9A1ABE97631C828E41815F34FDCDF787419FE13A3137649AA93D2584230DF5F24B5C00C88B7D7DE4367693428C730376F218A53E853B0851BAB7C53C15DA7839CBE1285DB63F6FA45C1BB59FE1C5BB918F0F8459D7EF60ACFF5C0FA0F3FCAD1C5F4CE4416D4F4B36B05CDCEBE4FB879E95847EFBC6449CD190248843BC7EDB145FBFC4EDBB1A3C959298F08F3BA2CFBE231BBE204BE6F906209D28BD4820AB3E7BE96C26AE8A809ADD8D1A5A0B008E9570FA4C4697E116B8119892C6042936814C2FFB |
| 124 | +
|
| 125 | + 20120821050046 2 6 100 2047 2 DD2047CBDBB6F8E919BC63DE885B34D0FD6E3DB2887D8B46FE249886ACED6B46DFCD5553168185FD376122171CD8927E60120FA8D01F01D03E58281FEA9A1ABE97631C828E41815F34FDCDF787419FE13A3137649AA93D2584230DF5F24B5C00C88B7D7DE4367693428C730376F218A53E853B0851BAB7C53C15DA7839CBE1285DB63F6FA45C1BB59FE1C5BB918F0F8459D7EF60ACFF5C0FA0F3FCAD1C5F4CE4416D4F4B36B05CDCEBE4FB879E95847EFBC6449CD190248843BC7EDB145FBFC4EDBB1A3C959298F08F3BA2CFBE231BBE204BE6F906209D28BD4820AB3E7BE96C26AE8A809ADD8D1A5A0B008E9570FA4C4697E116B8119892C60429368214FC53 |
| 126 | +
|
| 127 | + 20120821050054 2 6 100 2047 5 DD2047CBDBB6F8E919BC63DE885B34D0FD6E3DB2887D8B46FE249886ACED6B46DFCD5553168185FD376122171CD8927E60120FA8D01F01D03E58281FEA9A1ABE97631C828E41815F34FDCDF787419FE13A3137649AA93D2584230DF5F24B5C00C88B7D7DE4367693428C730376F218A53E853B0851BAB7C53C15DA7839CBE1285DB63F6FA45C1BB59FE1C5BB918F0F8459D7EF60ACFF5C0FA0F3FCAD1C5F4CE4416D4F4B36B05CDCEBE4FB879E95847EFBC6449CD190248843BC7EDB145FBFC4EDBB1A3C959298F08F3BA2CFBE231BBE204BE6F906209D28BD4820AB3E7BE96C26AE8A809ADD8D1A5A0B008E9570FA4C4697E116B8119892C60429368218E83F |
| 128 | + ' |
| 129 | + provide_dsa_keys: false |
| 130 | + provide_ecdsa_keys: false |
| 131 | + provide_ed25519_keys: false |
| 132 | + provide_rsa_keys: false |
| 133 | + root_group: root |
| 134 | + rsa: |
| 135 | + private_key: '-----BEGIN RSA PRIVATE KEY----- |
| 136 | +
|
| 137 | + NOT_DEFINED |
| 138 | +
|
| 139 | + -----END RSA PRIVATE KEY----- |
| 140 | + ' |
| 141 | + public_key: 'ssh-rsa NOT_DEFINED |
| 142 | + ' |
| 143 | + server: openssh-server |
| 144 | + server_version: latest |
| 145 | + service: ssh |
| 146 | + ssh_config: /etc/ssh/ssh_config |
| 147 | + ssh_config_backup: true |
| 148 | + ssh_config_group: root |
| 149 | + ssh_config_mode: '644' |
| 150 | + ssh_config_src: ssh_config |
| 151 | + ssh_config_user: root |
| 152 | + ssh_known_hosts: /etc/ssh/ssh_known_hosts |
| 153 | + ssh_known_hosts_src: ssh_known_hosts |
| 154 | + ssh_moduli: /etc/ssh/moduli |
| 155 | + sshd_binary: /usr/sbin/sshd |
| 156 | + sshd_config: /etc/ssh/sshd_config |
| 157 | + sshd_config_backup: true |
| 158 | + sshd_config_group: root |
| 159 | + sshd_config_mode: '644' |
| 160 | + sshd_config_src: sshd_config |
| 161 | + sshd_config_user: root |
| 162 | + sshd_enable: true |
| 163 | + tofs: |
| 164 | + source_files: |
| 165 | + manage ssh_known_hosts file: |
| 166 | + - alt_ssh_known_hosts |
| 167 | + ssh_config: |
| 168 | + - alt_ssh_config |
| 169 | + sshd_banner: |
| 170 | + - fire_banner |
| 171 | + sshd_config: |
| 172 | + - alt_sshd_config |
| 173 | + ssh_config: |
| 174 | + Hosts: |
| 175 | + '*': |
| 176 | + GSSAPIAuthentication: 'yes' |
| 177 | + HashKnownHosts: 'yes' |
| 178 | + SendEnv: LANG LC_* |
| 179 | + sshd_config: |
| 180 | + AcceptEnv: LANG LC_* |
| 181 | + ChallengeResponseAuthentication: 'no' |
| 182 | + PrintMotd: 'no' |
| 183 | + Subsystem: sftp /usr/lib/openssh/sftp-server |
| 184 | + UsePAM: 'yes' |
| 185 | + X11Forwarding: 'yes' |
0 commit comments