fix role
This commit is contained in:
parent
615a9f85f0
commit
c331418ba0
2 changed files with 11 additions and 11 deletions
|
@ -1,25 +1,25 @@
|
||||||
---
|
---
|
||||||
cfssl_version: 1.6.3
|
cfssl_version: 1.6.3
|
||||||
cfssl_bin_directory: /usr/bin
|
cfssl_bin_directory: '/usr/bin'
|
||||||
cfssl_serve_url: localhost:8888
|
cfssl_serve_url: 'localhost:8888'
|
||||||
cfssl_profile: server_client
|
cfssl_profile: 'server_client'
|
||||||
cfssl_auth_key: "0123456789ABCDEF0123456789ABCDEF"
|
cfssl_auth_key: "0123456789ABCDEF0123456789ABCDEF"
|
||||||
|
|
||||||
crt_key:
|
crt_key:
|
||||||
algo: rsa
|
algo: 'rsa'
|
||||||
size: 4096
|
size: 4096
|
||||||
|
|
||||||
crt_names:
|
crt_names:
|
||||||
- C: FR
|
- C: 'FR'
|
||||||
L: 'Paris'
|
L: 'Paris'
|
||||||
O: 'Acme'
|
O: 'Acme'
|
||||||
OU: 'IT'
|
OU: 'IT'
|
||||||
|
|
||||||
ssl_dir: /etc/ssl
|
ssl_dir: '/etc/ssl'
|
||||||
cfssl_config_file: {{ssl_dir}}/cfssl.json
|
cfssl_config_file: '{{ssl_dir}}/cfssl.json'
|
||||||
cfssl_csr_file : {{ssl_dir}}/csr.json
|
cfssl_csr_file : '{{ssl_dir}}/csr.json'
|
||||||
key_file: {{ssl_dir}}/private/{{inventory_hostname_short}}.key
|
key_file: '{{ssl_dir}}/private/{{inventory_hostname_short}}.key'
|
||||||
cert_file: {{ssl_dir}}certs/{{inventory_hostname_short}}.pem
|
cert_file: '{{ssl_dir}}/certs/{{inventory_hostname_short}}.pem'
|
||||||
|
|
||||||
integrate_ca: yes
|
integrate_ca: yes
|
||||||
ca_filename : my_intermediate_ca.crt
|
ca_filename : my_intermediate_ca.crt
|
|
@ -26,7 +26,7 @@
|
||||||
shell: 'mv {{ssl_dir}}/{{inventory_hostname_short}}-key.pem {{key_file}}'
|
shell: 'mv {{ssl_dir}}/{{inventory_hostname_short}}-key.pem {{key_file}}'
|
||||||
|
|
||||||
- name: move cert file to {{cert_file}}
|
- name: move cert file to {{cert_file}}
|
||||||
hell: 'mv {{ssl_dir}}/{{inventory_hostname_short}}.pem {{cert_file}}'
|
shell: 'mv {{ssl_dir}}/{{inventory_hostname_short}}.pem {{cert_file}}'
|
||||||
|
|
||||||
- name: recuperate ca certificate
|
- name: recuperate ca certificate
|
||||||
shell: '{{cfssl_bin_directory}}/cfssl info -remote "{{cfssl_serve_url}}" | cfssljson -bare -stdout > /usr/local/share/ca-certificates/{{ca_filename}}'
|
shell: '{{cfssl_bin_directory}}/cfssl info -remote "{{cfssl_serve_url}}" | cfssljson -bare -stdout > /usr/local/share/ca-certificates/{{ca_filename}}'
|
||||||
|
|
Loading…
Reference in a new issue