refactor: use the file extension .yml for all yaml files
The role used .yaml while the molecule scenario used .yml, because molecule hard codes molecule.yml and has no fallback for the other extension. Aligning all files on .yml keeps the extension consistent across the repository and avoids surprises when a tool only supports one of both spellings. Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
---
|
||||
|
||||
- name: Create private key for intermediate CA
|
||||
community.crypto.openssl_privatekey:
|
||||
path: "{{ certificate_authority_intermediate_ca_path }}/privkey.pem"
|
||||
mode: "0600"
|
||||
type: "{{ certificate_authority_intermediate_ca_tls_key_type }}"
|
||||
|
||||
- name: Create a certificate signing request (CSR) for intermediate CA
|
||||
community.crypto.openssl_csr:
|
||||
basic_constraints:
|
||||
- "CA:TRUE"
|
||||
common_name: "{{ certificate_authority_intermediate_ca_common_name }}"
|
||||
countryName: "{{ certificate_authority_intermediate_ca_country_name }}"
|
||||
email_address: "{{ certificate_authority_intermediate_ca_email_address }}"
|
||||
organization_name: "{{ certificate_authority_intermediate_ca_organization_name }}"
|
||||
organizational_unit_name: "{{ certificate_authority_intermediate_ca_organizational_unit_name }}"
|
||||
path: "{{ certificate_authority_intermediate_ca_path }}/cert-req.pem"
|
||||
privatekey_path: "{{ certificate_authority_intermediate_ca_path }}/privkey.pem"
|
||||
state_or_province_name: "{{ certificate_authority_intermediate_ca_state_or_province_name }}"
|
||||
subject_alt_name: "{{ certificate_authority_intermediate_ca_subject_alternative_names if certificate_authority_intermediate_ca_subject_alternative_names | length > 0 else omit }}"
|
||||
use_common_name_for_san: false
|
||||
|
||||
- name: Create signed client certificate - unprotected root Certificate Authority (CA)
|
||||
community.crypto.x509_certificate:
|
||||
csr_path: "{{ certificate_authority_intermediate_ca_path }}/cert-req.pem"
|
||||
ownca_not_after: "{{ certificate_authority_intermediate_ca_not_after }}"
|
||||
ownca_not_before: "{{ certificate_authority_intermediate_ca_not_before }}"
|
||||
ownca_path: "{{ certificate_authority_root_ca_path }}/cert.pem"
|
||||
ownca_privatekey_path: "{{ certificate_authority_root_ca_path }}/privkey.pem"
|
||||
path: "{{ certificate_authority_intermediate_ca_path }}/cert.pem"
|
||||
provider: ownca
|
||||
when: certificate_authority_root_ca_tls_key_passphrase | length <= 0
|
||||
|
||||
- name: Create signed client certificate - passphrase protected root Certificate Authority (CA)
|
||||
community.crypto.x509_certificate:
|
||||
csr_path: "{{ certificate_authority_intermediate_ca_path }}/cert-req.pem"
|
||||
ownca_not_after: "{{ certificate_authority_intermediate_ca_not_after }}"
|
||||
ownca_not_before: "{{ certificate_authority_intermediate_ca_not_before }}"
|
||||
ownca_path: "{{ certificate_authority_root_ca_path }}/cert.pem"
|
||||
ownca_privatekey_passphrase: "{{ certificate_authority_root_ca_tls_key_passphrase }}"
|
||||
ownca_privatekey_path: "{{ certificate_authority_root_ca_path }}/privkey.pem"
|
||||
path: "{{ certificate_authority_intermediate_ca_path }}/cert.pem"
|
||||
provider: ownca
|
||||
when: certificate_authority_root_ca_tls_key_passphrase | length > 0
|
||||
Reference in New Issue
Block a user