From 1d093fd18aaad5dac4919b8b53c6d616bf72ccd0 Mon Sep 17 00:00:00 2001 From: Daniel Berteaud Date: Mon, 21 Mar 2016 18:24:12 +0100 Subject: [PATCH] Add TLS support of Zabbix 3.0 --- .../templates/etc/zabbix/zabbix_proxy.conf/85TLS | 33 ++++++++++++++++++++++ 1 file changed, 33 insertions(+) create mode 100644 root/etc/e-smith/templates/etc/zabbix/zabbix_proxy.conf/85TLS diff --git a/root/etc/e-smith/templates/etc/zabbix/zabbix_proxy.conf/85TLS b/root/etc/e-smith/templates/etc/zabbix/zabbix_proxy.conf/85TLS new file mode 100644 index 0000000..0e31f1e --- /dev/null +++ b/root/etc/e-smith/templates/etc/zabbix/zabbix_proxy.conf/85TLS @@ -0,0 +1,33 @@ +{ + my @encryptions = (); + my $psk_file = ${'zabbix-proxy'}{'TLSPSKFile'} || '/etc/zabbix/zabbix_proxy.psk'; + my $psk_id = ${'zabbix-proxy'}{'TLSPSKIdentity'} || $SystemName . '.' . $DomainName . '-proxy'; + if (-s $psk_file){ + push @encryptions, 'psk'; + $OUT .=<<_EOF; +TLSPSKFile=$psk_file +TLSPSKIdentity=$psk_id +_EOF + } + + my $cert = ${'zabbix-proxy'}{'TLSCertFile'} || '/etc/zabbix/zabbix_proxy.crt'; + my $key = ${'zabbix-proxy'}{'TLSKeyFile'} || '/etc/zabbix/zabbix_proxy.key'; + my $ca = ${'zabbix-proxy'}{'TLSCAFile'} || '/etc/zabbix/zabbix_proxy.ca'; + if (-s $cert && -s $key && -s $ca){ + push @encryptions, 'cert'; + $OUT .=<<_EOF; +TLSCertFile=$cert +TLSKeyFile=$key +TLSCAFile=$ca +_EOF + my $issuer = ${'zabbix-proxy'}{'TLSServerCertIssuer'} || ''; + my $subject = ${'zabbix-proxy'}{'TLSServerCertSubject'} || ''; + $OUT .= "TLSServerCertIssuer=$issuer\n" if ($issuer ne ''); + $OUT .= "TLSServerCertSubject=$subject\n" if ($subject ne ''); + } + my $encryptions = (scalar @encryptions > 0) ? join(',', @encryptions) : 'unencrypted'; + $OUT .=<<_EOF; +TLSConnect=$encryptions +TLSAccept=$encryptions +_EOF +}