feat: assert that the signing certificate authority is available

Issuing an intermediate certificate authority or a client certificate always
signs against the private key of the parent authority, regardless of whether
that authority is managed in the same run. With `certificate_authority_root_ca_skip`
or `certificate_authority_intermediate_ca_skip` enabled and no previously
provisioned key at the configured path, this surfaced as a generic module error
deep inside the signing task.

Stat the parent private key upfront and assert its presence, so the failure
names the missing path and the variables that control it. Skipping the parent
remains valid when its key already exists, because the check inspects the file
instead of the skip variable.

Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
2026-09-07 22:30:23 +02:00
co-authored by Copilot
parent 9ea26dc23f
commit ad7b76852b
2 changed files with 34 additions and 0 deletions
+17
View File
@@ -8,6 +8,23 @@
mode: "0700"
state: directory
- name: Verify that the signing intermediate Certificate Authority (CA) is available
when: certificate_authority_client_create is defined and
certificate_authority_client_create
block:
- name: Check private key of the intermediate Certificate Authority (CA)
ansible.builtin.stat:
path: "{{ certificate_authority_intermediate_ca_path }}/privkey.pem"
register: _intermediate_ca_privkey
- name: Assert that the private key of the intermediate Certificate Authority (CA) exists
ansible.builtin.assert:
that: _intermediate_ca_privkey.stat.exists
fail_msg: >-
Signing the client certificate requires
{{ certificate_authority_intermediate_ca_path }}/privkey.pem. Either unset
certificate_authority_intermediate_ca_skip so the intermediate certificate authority is
created or imported, or point certificate_authority_intermediate_ca_path to an existing one.
- name: Create unprotected client certificate
ansible.builtin.include_tasks: client_certificate_unprotected.yaml
when: certificate_authority_client_create is defined and