SSH known_hosts config
authorOliver Walsh <owalsh@redhat.com>
Fri, 24 Mar 2017 14:35:09 +0000 (14:35 +0000)
committerOliver Walsh <owalsh@redhat.com>
Thu, 13 Apr 2017 20:53:59 +0000 (21:53 +0100)
commit7d3552a105ad5aa62cad0998c11df5ec6bd06ed6
tree38e0f69556cdce84f14a95e04e50a56d1a7a0ac5
parent8716d9f769dd17ef17fef7f0fdefaf0df6a7fe24
SSH known_hosts config

Fetch the host public keys from each node, combine them all and write to the
system-wide ssh known hosts. The alternative of disabling host key
 verification is vulnerable to a MITM attack.

Change-Id: Ib572b5910720b1991812256e68c975f7fbe2239c
extraconfig/tasks/ssh/host_public_key.yaml [new file with mode: 0644]
extraconfig/tasks/ssh/known_hosts_config.yaml [new file with mode: 0644]
overcloud-resource-registry-puppet.j2.yaml
overcloud.j2.yaml
puppet/blockstorage-role.yaml
puppet/cephstorage-role.yaml
puppet/compute-role.yaml
puppet/controller-role.yaml
puppet/objectstorage-role.yaml
puppet/role.role.j2.yaml
releasenotes/notes/ssh_known_hosts-287563590632d1aa.yaml [new file with mode: 0644]