diff --git a/README.md b/README.md index 12e794a..1a5fe57 100644 --- a/README.md +++ b/README.md @@ -34,7 +34,7 @@ certificate_authority_client_subject_alternative_names: | `certificate_authority_root_ca_organization_name` | Organization name of the root certificate authority owner. | `""` | | `certificate_authority_root_ca_organizational_unit_name` | Organizational unit name of the root certificate authority. | `""` | | `certificate_authority_root_ca_state_or_province_name` | State or province name where the owner of the root certificate authority is located. | `""` | -| `certificate_authority_root_ca_subject_alternative_names` | Subject Alternative Names (SAN) of the root certificate authority. Each entry must be prefixed by its type, for example `DNS:example.local` or `IP:10.11.12.13`. | `[]` | +| `certificate_authority_root_ca_subject_alternative_names` | Subject Alternative Names (SAN) of the root certificate authority. Example: `DNS:example.local`, `IP:10.11.12.13`. | `[]` | | `certificate_authority_root_ca_not_after` | Time in the future from now when the TLS certificate should expire | `+3650d` | | `certificate_authority_root_ca_not_before` | Time in the past from now when the TLS certificate should be valid. | `+0s` | | `certificate_authority_root_ca_tls_key_content` | Content of a custom used root certificate authority. Will only be imported, when `certificate_authority_root_ca_create: false`. | `""` | @@ -55,7 +55,7 @@ certificate_authority_client_subject_alternative_names: | `certificate_authority_intermediate_ca_organization_name` | Organization name of the intermediate certificate authority owner. | `""` | | `certificate_authority_intermediate_ca_organizational_unit_name` | Organizational unit name of the intermediate certificate authority. | `""` | | `certificate_authority_intermediate_ca_state_or_province_name` | State or province name where the owner of the intermediate certificate authority is located. | `""` | -| `certificate_authority_intermediate_ca_subject_alternative_names` | Subject Alternative Names (SAN) of the intermediate certificate authority. Each entry must be prefixed by its type, for example `DNS:example.local` or `IP:10.11.12.13`. | `[]` | +| `certificate_authority_intermediate_ca_subject_alternative_names` | Subject Alternative Names (SAN) of the intermediate certificate authority. Example: `DNS:example.local`, `IP:10.11.12.13`. | `[]` | | `certificate_authority_intermediate_ca_not_after` | Time in the future from now when the TLS certificate should expire | `+1825d` | | `certificate_authority_intermediate_ca_not_before` | Time in the past from now when the TLS certificate should be valid. | `+0s` | | `certificate_authority_intermediate_ca_tls_key_content` | Content of a custom used intermediate certificate authority. Will only be imported, when `certificate_authority_intermediate_ca_create: false`. | `""` | @@ -76,7 +76,7 @@ certificate_authority_client_subject_alternative_names: | `certificate_authority_client_organization_name` | Organization name of the client certificate owner. | `""` | | `certificate_authority_client_organizational_unit_name` | Common Name (CN) of the client certificate. | `""` | | `certificate_authority_client_state_or_province_name` | State or province name where the owner of the client certificate is located. | `""` | -| `certificate_authority_client_subject_alternative_names` | Subject Alternative Names (SAN) of the client certificate. Each entry must be prefixed by its type, for example `DNS:example.local` or `IP:10.11.12.13`. | `[]` | +| `certificate_authority_client_subject_alternative_names` | Subject Alternative Names (SAN) of the client certificate. Example: `DNS:example.local`, `IP:10.11.12.13`. | `[]` | | `certificate_authority_client_not_after` | Time in the future from now when the TLS certificate should expire | `+397d` | | `certificate_authority_client_not_before` | Time in the past from now when the TLS certificate should be valid. | `+0s` | | `certificate_authority_client_tls_key_passphrase` | Passphrase for the private key of the generated or imported client certificate. | `""` | diff --git a/defaults/main.yaml b/defaults/main.yaml index 40146a1..050d940 100644 --- a/defaults/main.yaml +++ b/defaults/main.yaml @@ -15,7 +15,7 @@ certificate_authority_root_ca_import: true ## @param certificate_authority_root_ca_organization_name Organization name of the root certificate authority owner. ## @param certificate_authority_root_ca_organizational_unit_name Organizational unit name of the root certificate authority. ## @param certificate_authority_root_ca_state_or_province_name State or province name where the owner of the root certificate authority is located. -## @param certificate_authority_root_ca_subject_alternative_names Subject Alternative Names (SAN) of the root certificate authority. Each entry must be prefixed by its type, for example `DNS:example.local` or `IP:10.11.12.13`. +## @param certificate_authority_root_ca_subject_alternative_names Subject Alternative Names (SAN) of the root certificate authority. Example: `DNS:example.local`, `IP:10.11.12.13`. ## @param certificate_authority_root_ca_not_after Time in the future from now when the TLS certificate should expire ## @param certificate_authority_root_ca_not_before Time in the past from now when the TLS certificate should be valid. certificate_authority_root_ca_path: "/etc/ansible-playbook/pki/ca" @@ -53,7 +53,7 @@ certificate_authority_intermediate_ca_create: true ## @param certificate_authority_intermediate_ca_organization_name Organization name of the intermediate certificate authority owner. ## @param certificate_authority_intermediate_ca_organizational_unit_name Organizational unit name of the intermediate certificate authority. ## @param certificate_authority_intermediate_ca_state_or_province_name State or province name where the owner of the intermediate certificate authority is located. -## @param certificate_authority_intermediate_ca_subject_alternative_names Subject Alternative Names (SAN) of the intermediate certificate authority. Each entry must be prefixed by its type, for example `DNS:example.local` or `IP:10.11.12.13`. +## @param certificate_authority_intermediate_ca_subject_alternative_names Subject Alternative Names (SAN) of the intermediate certificate authority. Example: `DNS:example.local`, `IP:10.11.12.13`. ## @param certificate_authority_intermediate_ca_not_after Time in the future from now when the TLS certificate should expire ## @param certificate_authority_intermediate_ca_not_before Time in the past from now when the TLS certificate should be valid. certificate_authority_intermediate_ca_path: "/etc/ansible-playbook/pki/intermediate" @@ -91,7 +91,7 @@ certificate_authority_client_create: true ## @param certificate_authority_client_organization_name Organization name of the client certificate owner. ## @param certificate_authority_client_organizational_unit_name Common Name (CN) of the client certificate. ## @param certificate_authority_client_state_or_province_name State or province name where the owner of the client certificate is located. -## @param certificate_authority_client_subject_alternative_names Subject Alternative Names (SAN) of the client certificate. Each entry must be prefixed by its type, for example `DNS:example.local` or `IP:10.11.12.13`. +## @param certificate_authority_client_subject_alternative_names Subject Alternative Names (SAN) of the client certificate. Example: `DNS:example.local`, `IP:10.11.12.13`. ## @param certificate_authority_client_not_after Time in the future from now when the TLS certificate should expire ## @param certificate_authority_client_not_before Time in the past from now when the TLS certificate should be valid. certificate_authority_client_path: "/etc/ansible-playbook/pki/client" diff --git a/meta/argument_specs.yaml b/meta/argument_specs.yaml index c5451bd..afac55e 100644 --- a/meta/argument_specs.yaml +++ b/meta/argument_specs.yaml @@ -49,7 +49,7 @@ argument_specs: type: str default: "" certificate_authority_root_ca_subject_alternative_names: - description: "Subject Alternative Names (SAN) of the root certificate authority. Each entry must be prefixed by its type, for example DNS:example.local or IP:10.11.12.13." + description: "Subject Alternative Names (SAN) of the root certificate authority. Example: DNS:example.local, IP:10.11.12.13." type: list elements: str default: [] @@ -121,7 +121,7 @@ argument_specs: type: str default: "" certificate_authority_intermediate_ca_subject_alternative_names: - description: "Subject Alternative Names (SAN) of the intermediate certificate authority. Each entry must be prefixed by its type, for example DNS:example.local or IP:10.11.12.13." + description: "Subject Alternative Names (SAN) of the intermediate certificate authority. Example: DNS:example.local, IP:10.11.12.13." type: list elements: str default: [] @@ -193,7 +193,7 @@ argument_specs: type: str default: "" certificate_authority_client_subject_alternative_names: - description: "Subject Alternative Names (SAN) of the client certificate. Each entry must be prefixed by its type, for example DNS:example.local or IP:10.11.12.13." + description: "Subject Alternative Names (SAN) of the client certificate. Example: DNS:example.local, IP:10.11.12.13." type: list elements: str default: []