dev-sec / dev-sec/chef-ssh-hardening
Why not wrap openssh cookbook
Nobody has claimed this yet.
- Dominant language
- Ruby
- Stars
- 168
- Forks
- 66
- Avg merge
- 9h 10m
- Merged PRs (30d)
- 2
Description
Hi,
I like what you're trying to do here, but I've a couple of questions with regard to the approach.
As it stands this cookbook is incompatible with the openssh-cookbook as it tries to change the same files.
( https://github.com/opscode-cookbooks/openssh )
It would seem sensible to me for this to be a wrapper around openssh-cookbook which sets sensible, secure defaults
Did you consider this as an option? If so why did you not go this way?
Edit to add: I'd be happy to file a PR with this re-worked as a wrapper, if you're open to the idea.
thanks
Andrew
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review the existing chef-ssh-hardening cookbook and its interaction with the openssh cookbook. Confirm whether a wrapper is desired, then define the affected files and acceptance criteria before starting; the issue does not name specific files or tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ruby
- Domain
- devops, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100