mirror of
https://github.com/cwchristerw/tjas-infra
synced 2025-12-02 20:53:40 +00:00
Compare commits
1 Commits
master
...
19a08cffa5
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
19a08cffa5 |
@@ -546,9 +546,6 @@
|
|||||||
path: "/root/data/openssl/{{ cert }}/cert.pem"
|
path: "/root/data/openssl/{{ cert }}/cert.pem"
|
||||||
privatekey_path: "/root/data/openssl/{{ cert }}/privkey.pem"
|
privatekey_path: "/root/data/openssl/{{ cert }}/privkey.pem"
|
||||||
csr_path: "/root/data/openssl/{{ cert }}/csr.pem"
|
csr_path: "/root/data/openssl/{{ cert }}/csr.pem"
|
||||||
provider: "ownca"
|
|
||||||
ownca_path: /etc/ssl/crt/ansible_CA.crt
|
|
||||||
ownca_privatekey_path: /etc/ssl/private/ansible_CA.pem
|
|
||||||
provider: selfsigned
|
provider: selfsigned
|
||||||
selfsigned_not_after: "+7300d"
|
selfsigned_not_after: "+7300d"
|
||||||
loop: "{{ config.openssl.certificates.keys() | list }}"
|
loop: "{{ config.openssl.certificates.keys() | list }}"
|
||||||
@@ -569,7 +566,6 @@
|
|||||||
provider: "ownca"
|
provider: "ownca"
|
||||||
ownca_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/cert.pem"
|
ownca_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/cert.pem"
|
||||||
ownca_privatekey_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/privkey.pem"
|
ownca_privatekey_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/privkey.pem"
|
||||||
provider: ownca
|
|
||||||
ownca_not_after: "+365d"
|
ownca_not_after: "+365d"
|
||||||
loop: "{{ config.openssl.certificates.keys() | list }}"
|
loop: "{{ config.openssl.certificates.keys() | list }}"
|
||||||
loop_control:
|
loop_control:
|
||||||
@@ -590,7 +586,6 @@
|
|||||||
provider: "ownca"
|
provider: "ownca"
|
||||||
ownca_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/cert.pem"
|
ownca_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/cert.pem"
|
||||||
ownca_privatekey_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/privkey.pem"
|
ownca_privatekey_path: "/root/data/openssl/{{ config.openssl.certificates[cert].issuer }}/privkey.pem"
|
||||||
provider: ownca
|
|
||||||
ownca_not_after: "+30d"
|
ownca_not_after: "+30d"
|
||||||
loop: "{{ config.openssl.certificates.keys() | list }}"
|
loop: "{{ config.openssl.certificates.keys() | list }}"
|
||||||
loop_control:
|
loop_control:
|
||||||
@@ -606,7 +601,7 @@
|
|||||||
- name: "Deployer - OpenSSL - Configure - Generate Fullchain"
|
- name: "Deployer - OpenSSL - Configure - Generate Fullchain"
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
dest: "/root/data/openssl/{{ cert }}/fullchain.pem"
|
dest: "/root/data/openssl/{{ cert }}/fullchain.pem"
|
||||||
content: "{{ lookup('ansible.builtin.file', '/root/data/openssl/{{ cert }}/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/' + config.openssl.certificates[cert].issuer + '/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/root/cert.pem') }}"
|
content: "{{ lookup('ansible.builtin.file', '/root/data/openssl/' + cert + '/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/' + config.openssl.certificates[cert].issuer + '/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/root/cert.pem') }}"
|
||||||
loop: "{{ config.openssl.certificates.keys() | list }}"
|
loop: "{{ config.openssl.certificates.keys() | list }}"
|
||||||
loop_control:
|
loop_control:
|
||||||
label: "{{ cert }}"
|
label: "{{ cert }}"
|
||||||
@@ -621,7 +616,7 @@
|
|||||||
- name: "Deployer - OpenSSL - Configure - Generate Chain"
|
- name: "Deployer - OpenSSL - Configure - Generate Chain"
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
dest: "/root/data/openssl/{{ cert }}/chain.pem"
|
dest: "/root/data/openssl/{{ cert }}/chain.pem"
|
||||||
content: "{{ lookup('ansible.builtin.file', '/root/data/openssl/{{ cert }}/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/' + config.openssl.certificates[cert].issuer + '/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/root/cert.pem') }}"
|
content: "{{ lookup('ansible.builtin.file', '/root/data/openssl/' + cert + '/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/' + config.openssl.certificates[cert].issuer + '/cert.pem') }}{{ lookup('ansible.builtin.file', '/root/data/openssl/root/cert.pem') }}"
|
||||||
loop: "{{ config.openssl.certificates.keys() | list }}"
|
loop: "{{ config.openssl.certificates.keys() | list }}"
|
||||||
loop_control:
|
loop_control:
|
||||||
label: "{{ cert }}"
|
label: "{{ cert }}"
|
||||||
|
|||||||
Reference in New Issue
Block a user