diff options
| author | Carlos Konstanski <ckonstanski@pippiandcarlos.com> | 2018-01-16 14:56:49 -0700 |
|---|---|---|
| committer | Carlos Konstanski <ckonstanski@pippiandcarlos.com> | 2018-01-16 14:56:49 -0700 |
| commit | 0f028e9ea256041cb25ddf6d40c2de360039444d (patch) | |
| tree | dc98e1635532c4f379d8e374bf240462f359e15f /salt | |
| parent | 3de7899e498e54f6661a780a64ed890853e56e90 (diff) | |
more ssl.yaml fixes
Diffstat (limited to 'salt')
| -rw-r--r-- | salt/openbook/ansible/files/ssl.yaml | 49 |
1 files changed, 26 insertions, 23 deletions
diff --git a/salt/openbook/ansible/files/ssl.yaml b/salt/openbook/ansible/files/ssl.yaml index fad5563..bc72779 100644 --- a/salt/openbook/ansible/files/ssl.yaml +++ b/salt/openbook/ansible/files/ssl.yaml @@ -1,24 +1,27 @@ --- -- name: "Create self-signed SSL cert" - shell: - cmd: | - if [ ! -f "/etc/ssl/certs/{{ item }}.crt" ] && [ ! -f "/etc/ssl/private/{{ item }}.key" ]; then - openssl req -x509 -nodes -sha256 -days 3650 -newkey rsa:4096 -keyout "/tmp/{{ item }}.key" -out "/tmp/{{ item }}.crt" <<EOF - US - New Jersey - Basking Ridge - Verizon Wireless - Verizon Cloud Platform - {{ item }} - carlos.konstanski@verizonwireless.com - EOF - cp -f "/tmp/{{ item }}.crt" "/etc/ssl/certs/" - cp -f "/tmp/{{ item }}.key" "/etc/ssl/private/" - chmod 644 "/etc/ssl/certs/{{ item }}.crt" - chown root: "/etc/ssl/certs/{{ item }}.crt" - chmod 640 "/etc/ssl/private/{{ item }}.key" - chown root:ssl-cert "/etc/ssl/private/{{ item }}.key" - fi - executable: /bin/bash - with_items: - - "{{ inventory_hostname }}" +- name: "SSl cert" + hosts: target + tasks: + - name: "Create self-signed SSL cert" + shell: + cmd: | + if [ ! -f "/etc/ssl/certs/{{ item }}.crt" ] && [ ! -f "/etc/ssl/private/{{ item }}.key" ]; then + openssl req -x509 -nodes -sha256 -days 3650 -newkey rsa:4096 -keyout "/tmp/{{ item }}.key" -out "/tmp/{{ item }}.crt" <<EOF + US + New Jersey + Basking Ridge + Verizon Wireless + Verizon Cloud Platform + {{ item }} + carlos.konstanski@verizonwireless.com + EOF + cp -f "/tmp/{{ item }}.crt" "/etc/ssl/certs/" + cp -f "/tmp/{{ item }}.key" "/etc/ssl/private/" + chmod 644 "/etc/ssl/certs/{{ item }}.crt" + chown root: "/etc/ssl/certs/{{ item }}.crt" + chmod 640 "/etc/ssl/private/{{ item }}.key" + chown root:ssl-cert "/etc/ssl/private/{{ item }}.key" + fi + executable: /bin/bash + with_items: + - "{{ inventory_hostname }}" |
