summaryrefslogtreecommitdiff
path: root/salt
diff options
context:
space:
mode:
authorCarlos Konstanski <ckonstanski@pippiandcarlos.com>2018-01-16 14:56:49 -0700
committerCarlos Konstanski <ckonstanski@pippiandcarlos.com>2018-01-16 14:56:49 -0700
commit0f028e9ea256041cb25ddf6d40c2de360039444d (patch)
treedc98e1635532c4f379d8e374bf240462f359e15f /salt
parent3de7899e498e54f6661a780a64ed890853e56e90 (diff)
more ssl.yaml fixes
Diffstat (limited to 'salt')
-rw-r--r--salt/openbook/ansible/files/ssl.yaml49
1 files changed, 26 insertions, 23 deletions
diff --git a/salt/openbook/ansible/files/ssl.yaml b/salt/openbook/ansible/files/ssl.yaml
index fad5563..bc72779 100644
--- a/salt/openbook/ansible/files/ssl.yaml
+++ b/salt/openbook/ansible/files/ssl.yaml
@@ -1,24 +1,27 @@
---
-- name: "Create self-signed SSL cert"
- shell:
- cmd: |
- if [ ! -f "/etc/ssl/certs/{{ item }}.crt" ] && [ ! -f "/etc/ssl/private/{{ item }}.key" ]; then
- openssl req -x509 -nodes -sha256 -days 3650 -newkey rsa:4096 -keyout "/tmp/{{ item }}.key" -out "/tmp/{{ item }}.crt" <<EOF
- US
- New Jersey
- Basking Ridge
- Verizon Wireless
- Verizon Cloud Platform
- {{ item }}
- carlos.konstanski@verizonwireless.com
- EOF
- cp -f "/tmp/{{ item }}.crt" "/etc/ssl/certs/"
- cp -f "/tmp/{{ item }}.key" "/etc/ssl/private/"
- chmod 644 "/etc/ssl/certs/{{ item }}.crt"
- chown root: "/etc/ssl/certs/{{ item }}.crt"
- chmod 640 "/etc/ssl/private/{{ item }}.key"
- chown root:ssl-cert "/etc/ssl/private/{{ item }}.key"
- fi
- executable: /bin/bash
- with_items:
- - "{{ inventory_hostname }}"
+- name: "SSl cert"
+ hosts: target
+ tasks:
+ - name: "Create self-signed SSL cert"
+ shell:
+ cmd: |
+ if [ ! -f "/etc/ssl/certs/{{ item }}.crt" ] && [ ! -f "/etc/ssl/private/{{ item }}.key" ]; then
+ openssl req -x509 -nodes -sha256 -days 3650 -newkey rsa:4096 -keyout "/tmp/{{ item }}.key" -out "/tmp/{{ item }}.crt" <<EOF
+ US
+ New Jersey
+ Basking Ridge
+ Verizon Wireless
+ Verizon Cloud Platform
+ {{ item }}
+ carlos.konstanski@verizonwireless.com
+ EOF
+ cp -f "/tmp/{{ item }}.crt" "/etc/ssl/certs/"
+ cp -f "/tmp/{{ item }}.key" "/etc/ssl/private/"
+ chmod 644 "/etc/ssl/certs/{{ item }}.crt"
+ chown root: "/etc/ssl/certs/{{ item }}.crt"
+ chmod 640 "/etc/ssl/private/{{ item }}.key"
+ chown root:ssl-cert "/etc/ssl/private/{{ item }}.key"
+ fi
+ executable: /bin/bash
+ with_items:
+ - "{{ inventory_hostname }}"