blob: bc72779e560091d50a135d751f45548ca5d60c1f (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
|
---
- name: "SSl cert"
hosts: target
tasks:
- name: "Create self-signed SSL cert"
shell:
cmd: |
if [ ! -f "/etc/ssl/certs/{{ item }}.crt" ] && [ ! -f "/etc/ssl/private/{{ item }}.key" ]; then
openssl req -x509 -nodes -sha256 -days 3650 -newkey rsa:4096 -keyout "/tmp/{{ item }}.key" -out "/tmp/{{ item }}.crt" <<EOF
US
New Jersey
Basking Ridge
Verizon Wireless
Verizon Cloud Platform
{{ item }}
carlos.konstanski@verizonwireless.com
EOF
cp -f "/tmp/{{ item }}.crt" "/etc/ssl/certs/"
cp -f "/tmp/{{ item }}.key" "/etc/ssl/private/"
chmod 644 "/etc/ssl/certs/{{ item }}.crt"
chown root: "/etc/ssl/certs/{{ item }}.crt"
chmod 640 "/etc/ssl/private/{{ item }}.key"
chown root:ssl-cert "/etc/ssl/private/{{ item }}.key"
fi
executable: /bin/bash
with_items:
- "{{ inventory_hostname }}"
|