refactor: use the file extension .yml for all yaml files
The role used .yaml while the molecule scenario used .yml, because molecule hard codes molecule.yml and has no fallback for the other extension. Aligning all files on .yml keeps the extension consistent across the repository and avoids surprises when a tool only supports one of both spellings. Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
---
|
||||
|
||||
- name: Create private key for client
|
||||
community.crypto.openssl_privatekey:
|
||||
path: "{{ certificate_authority_client_path }}/privkey.pem"
|
||||
mode: "0600"
|
||||
type: "{{ certificate_authority_client_tls_key_type }}"
|
||||
|
||||
- name: Create a certificate signing request (CSR) for client certificate
|
||||
community.crypto.openssl_csr:
|
||||
common_name: "{{ certificate_authority_client_common_name }}"
|
||||
countryName: "{{ certificate_authority_client_country_name }}"
|
||||
email_address: "{{ certificate_authority_client_email_address }}"
|
||||
extendedKeyUsage:
|
||||
- clientAuth
|
||||
- serverAuth
|
||||
organization_name: "{{ certificate_authority_client_organization_name }}"
|
||||
organizational_unit_name: "{{ certificate_authority_client_organizational_unit_name }}"
|
||||
path: "{{ certificate_authority_client_path }}/cert-req.pem"
|
||||
privatekey_path: "{{ certificate_authority_client_path }}/privkey.pem"
|
||||
state_or_province_name: "{{ certificate_authority_client_state_or_province_name }}"
|
||||
subject_alt_name: "{{ certificate_authority_client_subject_alternative_names if certificate_authority_client_subject_alternative_names | length > 0 else omit }}"
|
||||
|
||||
- name: Create signed client certificate - unprotected intermediate Certificate Authority (CA)
|
||||
community.crypto.x509_certificate:
|
||||
csr_path: "{{ certificate_authority_client_path }}/cert-req.pem"
|
||||
ownca_not_after: "{{ certificate_authority_client_not_after }}"
|
||||
ownca_not_before: "{{ certificate_authority_client_not_before }}"
|
||||
ownca_path: "{{ certificate_authority_intermediate_ca_path }}/cert.pem"
|
||||
ownca_privatekey_path: "{{ certificate_authority_intermediate_ca_path }}/privkey.pem"
|
||||
path: "{{ certificate_authority_client_path }}/cert.pem"
|
||||
provider: ownca
|
||||
when: certificate_authority_intermediate_ca_tls_key_passphrase | length <= 0
|
||||
|
||||
- name: Create signed client certificate - passphrase protected intermediate Certificate Authority (CA)
|
||||
community.crypto.x509_certificate:
|
||||
csr_path: "{{ certificate_authority_client_path }}/cert-req.pem"
|
||||
ownca_not_after: "{{ certificate_authority_client_not_after }}"
|
||||
ownca_not_before: "{{ certificate_authority_client_not_before }}"
|
||||
ownca_path: "{{ certificate_authority_intermediate_ca_path }}/cert.pem"
|
||||
ownca_privatekey_passphrase: "{{ certificate_authority_intermediate_ca_tls_key_passphrase }}"
|
||||
ownca_privatekey_path: "{{ certificate_authority_intermediate_ca_path }}/privkey.pem"
|
||||
path: "{{ certificate_authority_client_path }}/cert.pem"
|
||||
provider: ownca
|
||||
when: certificate_authority_intermediate_ca_tls_key_passphrase | length > 0
|
||||
Reference in New Issue
Block a user