mirror of
https://github.com/cwchristerw/tjas-infra
synced 2025-12-02 16:33:39 +00:00
Compare commits
2 Commits
ca83c7b07c
...
19a08cffa5
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
19a08cffa5 | ||
|
|
63a2160478 |
@@ -546,9 +546,6 @@
|
|||||||
path: "/root/data/openssl/{{ cert }}/cert.pem"
|
path: "/root/data/openssl/{{ cert }}/cert.pem"
|
||||||
privatekey_path: "/root/data/openssl/{{ cert }}/privkey.pem"
|
privatekey_path: "/root/data/openssl/{{ cert }}/privkey.pem"
|
||||||
csr_path: "/root/data/openssl/{{ cert }}/csr.pem"
|
csr_path: "/root/data/openssl/{{ cert }}/csr.pem"
|
||||||
provider: "ownca"
|
|
||||||
ownca_path: /etc/ssl/crt/ansible_CA.crt
|
|
||||||
ownca_privatekey_path: /etc/ssl/private/ansible_CA.pem
|
|
||||||
provider: selfsigned
|
provider: selfsigned
|
||||||
selfsigned_not_after: "+7300d"
|
selfsigned_not_after: "+7300d"
|
||||||
loop: "{{ config.openssl.certificates.keys() | list }}"
|
loop: "{{ config.openssl.certificates.keys() | list }}"
|
||||||
@@ -569,7 +566,6 @@
|
|||||||
provider: "ownca"
|
provider: "ownca"
|
||||||
ownca_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/cert.pem"
|
ownca_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/cert.pem"
|
||||||
ownca_privatekey_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/privkey.pem"
|
ownca_privatekey_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/privkey.pem"
|
||||||
provider: ownca
|
|
||||||
ownca_not_after: "+365d"
|
ownca_not_after: "+365d"
|
||||||
loop: "{{ config.openssl.certificates.keys() | list }}"
|
loop: "{{ config.openssl.certificates.keys() | list }}"
|
||||||
loop_control:
|
loop_control:
|
||||||
@@ -590,7 +586,6 @@
|
|||||||
provider: "ownca"
|
provider: "ownca"
|
||||||
ownca_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/cert.pem"
|
ownca_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/cert.pem"
|
||||||
ownca_privatekey_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/privkey.pem"
|
ownca_privatekey_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/privkey.pem"
|
||||||
provider: ownca
|
|
||||||
ownca_not_after: "+30d"
|
ownca_not_after: "+30d"
|
||||||
loop: "{{ config.openssl.certificates.keys() | list }}"
|
loop: "{{ config.openssl.certificates.keys() | list }}"
|
||||||
loop_control:
|
loop_control:
|
||||||
@@ -604,31 +599,30 @@
|
|||||||
- www
|
- www
|
||||||
|
|
||||||
- name: "Deployer - OpenSSL - Configure - Generate Fullchain"
|
- name: "Deployer - OpenSSL - Configure - Generate Fullchain"
|
||||||
community.crypto.certificate_complete_chain:
|
ansible.builtin.copy:
|
||||||
chain:
|
dest: "/root/data/openssl/{{ cert }}/fullchain.pem"
|
||||||
- "/root/data/openssl/{{ cert }}/cert.pem"
|
content: "{{ lookup('ansible.builtin.file', '/root/data/openssl/' + cert + '/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/' + config.openssl.certificates[cert].issuer + '/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/root/cert.pem') }}"
|
||||||
- "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/cert.pem"
|
|
||||||
path: "/root/data/openssl/{{ cert }}/fullchain.pem"
|
|
||||||
loop: "{{ config.openssl.certificates.keys() | list }}"
|
loop: "{{ config.openssl.certificates.keys() | list }}"
|
||||||
loop_control:
|
loop_control:
|
||||||
label: "{{ cert }}"
|
label: "{{ cert }}"
|
||||||
loop_var: "cert"
|
loop_var: "cert"
|
||||||
when:
|
when:
|
||||||
|
- config.openssl.certificates[cert].domains is defined
|
||||||
- config.openssl.certificates[cert].issuer is defined
|
- config.openssl.certificates[cert].issuer is defined
|
||||||
tags:
|
tags:
|
||||||
- openssl
|
- openssl
|
||||||
- www
|
- www
|
||||||
|
|
||||||
- name: "Deployer - OpenSSL - Configure - Generate Chain"
|
- name: "Deployer - OpenSSL - Configure - Generate Chain"
|
||||||
community.crypto.certificate_complete_chain:
|
ansible.builtin.copy:
|
||||||
chain:
|
dest: "/root/data/openssl/{{ cert }}/chain.pem"
|
||||||
- "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/cert.pem"
|
content: "{{ lookup('ansible.builtin.file', '/root/data/openssl/' + cert + '/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/' + config.openssl.certificates[cert].issuer + '/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/root/cert.pem') }}"
|
||||||
path: "/root/data/openssl/{{ cert }}/chain.pem"
|
|
||||||
loop: "{{ config.openssl.certificates.keys() | list }}"
|
loop: "{{ config.openssl.certificates.keys() | list }}"
|
||||||
loop_control:
|
loop_control:
|
||||||
label: "{{ cert }}"
|
label: "{{ cert }}"
|
||||||
loop_var: "cert"
|
loop_var: "cert"
|
||||||
when:
|
when:
|
||||||
|
- config.openssl.certificates[cert].domains is defined
|
||||||
- config.openssl.certificates[cert].issuer is defined
|
- config.openssl.certificates[cert].issuer is defined
|
||||||
tags:
|
tags:
|
||||||
- openssl
|
- openssl
|
||||||
|
|||||||
Reference in New Issue
Block a user