diff options
Diffstat (limited to 'files/ssl.yaml')
| -rw-r--r-- | files/ssl.yaml | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/files/ssl.yaml b/files/ssl.yaml new file mode 100644 index 0000000..6330e87 --- /dev/null +++ b/files/ssl.yaml @@ -0,0 +1,24 @@ +--- +- name: "Create self-signed SSL cert" + shell: + cmd: | + if [ ! -f "/etc/ssl/certs/{{ item }}.crt" ] && [ ! -f "/etc/ssl/private/{{ item }}.key" ]; then + openssl req -x509 -nodes -sha256 -days 3650 -newkey rsa:4096 -keyout "/tmp/{{ item }}.key" -out "/tmp/{{ item }}.crt" <<EOF + US + New Jersey + Basking Ridge + Verizon Wireless + Verizon Cloud Platform + {{ item }} + carlos.konstanski@verizonwireless.com + EOF + cp -f "/tmp/{{ item }}.crt" "/etc/ssl/certs/" + cp -f "/tmp/{{ item }}.key" "/etc/ssl/private/" + chmod 644 "/etc/ssl/certs/{{ item }}.crt" + chown root: "/etc/ssl/certs/{{ item }}.crt" + chmod 640 "/etc/ssl/private/{{ item }}.key" + chown root:ssl-cert "/etc/ssl/private/{{ item }}.key" + fi + executable: /bin/bash + with_items: + - "{{ inventory_hostname }}" |
