From bf34d6f423bd2da76938dfdc1cf4525dc17b97c5 Mon Sep 17 00:00:00 2001 From: Joey Hess Date: Sun, 4 Jan 2015 13:42:01 -0400 Subject: propellor spin --- src/Propellor/Property/DnsSec.hs | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) (limited to 'src/Propellor/Property/DnsSec.hs') diff --git a/src/Propellor/Property/DnsSec.hs b/src/Propellor/Property/DnsSec.hs index f76a28ff..47fa9b32 100644 --- a/src/Propellor/Property/DnsSec.hs +++ b/src/Propellor/Property/DnsSec.hs @@ -44,19 +44,18 @@ zoneSigned domain zonefile = RevertableProperty setup cleanup `requires` toProp (keysInstalled domain) cleanup = combineProperties ("removed signed zone for " ++ domain) - [ File.notPresent signedzonefile + [ File.notPresent (signedZoneFile zonefile) , File.notPresent dssetfile , toProp (revert (keysInstalled domain)) ] - signedzonefile = dir domain ++ ".signed" dssetfile = dir "-" ++ domain ++ "." dir = takeDirectory zonefile -- Need to update the signed zone file if the zone file or -- any of the keys have a newer timestamp. needupdate = do - v <- catchMaybeIO $ getModificationTime signedzonefile + v <- catchMaybeIO $ getModificationTime (signedZoneFile zonefile) case v of Nothing -> return True Just t1 -> anyM (newerthan t1) $ @@ -110,3 +109,7 @@ isPublic k = k `elem` [PubZSK, PubKSK] isZoneSigningKey :: DnsSecKey -> Bool isZoneSigningKey k = k `elem` [PubZSK, PrivZSK] + +-- | dnssec-signzone makes a .signed file +signedZoneFile :: FilePath -> FilePath +signedZoneFile zonefile = zonefile ++ ".signed" -- cgit v1.3-2-g0d8e