diff --git a/README.md b/README.md index 1a5fe57..d78c4f3 100644 --- a/README.md +++ b/README.md @@ -29,7 +29,7 @@ certificate_authority_client_subject_alternative_names: | `certificate_authority_root_ca_import` | Import the TLS certificate of the root certificate authority into the systems trust store. | `true` | | `certificate_authority_root_ca_path` | Directory where the private and public TLS key of the root certificate authority should be stored. | `/etc/ansible-playbook/pki/ca` | | `certificate_authority_root_ca_common_name` | Common Name (CN) of the root certificate authority. | `Ansible Root CA` | -| `certificate_authority_root_ca_country_name` | Common Name (CN) of the root certificate authority. For example `US`, `FR` or `DE`. | `""` | +| `certificate_authority_root_ca_country_name` | Country name of the root certificate authority. For example `US`, `FR` or `DE`. | `""` | | `certificate_authority_root_ca_email_address` | E-Mail Address of the root certificate authority owner. | `""` | | `certificate_authority_root_ca_organization_name` | Organization name of the root certificate authority owner. | `""` | | `certificate_authority_root_ca_organizational_unit_name` | Organizational unit name of the root certificate authority. | `""` | @@ -65,21 +65,21 @@ certificate_authority_client_subject_alternative_names: ### Client Certificate -| Name | Description | Value | -| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- | ---------------------------------- | -| `certificate_authority_client_skip` | Skip creation or import of a client certificate in general. | `true` | -| `certificate_authority_client_create` | Create client certificate from scratch or import via `certificate_authority_client_tls` prefixed variables. | `true` | -| `certificate_authority_client_path` | Directory where the private and public TLS key of the client certificate authority should be stored. | `/etc/ansible-playbook/pki/client` | -| `certificate_authority_client_common_name` | Common Name (CN) of the client certificate. | `Ansible Client Certificate` | -| `certificate_authority_client_country_name` | Country Name (CN) of the client certificate. For example `US`, `FR` or `DE`. | `""` | -| `certificate_authority_client_email_address` | E-Mail Address of the client certificate owner. | `""` | -| `certificate_authority_client_organization_name` | Organization name of the client certificate owner. | `""` | -| `certificate_authority_client_organizational_unit_name` | Common Name (CN) of the client certificate. | `""` | -| `certificate_authority_client_state_or_province_name` | State or province name where the owner of the client certificate is located. | `""` | -| `certificate_authority_client_subject_alternative_names` | Subject Alternative Names (SAN) of the client certificate. Example: `DNS:example.local`, `IP:10.11.12.13`. | `[]` | -| `certificate_authority_client_not_after` | Time in the future from now when the TLS certificate should expire | `+397d` | -| `certificate_authority_client_not_before` | Time in the past from now when the TLS certificate should be valid. | `+0s` | -| `certificate_authority_client_tls_key_passphrase` | Passphrase for the private key of the generated or imported client certificate. | `""` | -| `certificate_authority_client_tls_key_type` | Algorithm of the private key of the client certificate. | `RSA` | -| `certificate_authority_client_tls_crt_content` | Passphrase for the private key of the generated or imported client certificate. | `""` | -| `certificate_authority_client_tls_key_content` | Algorithm of the private key of the client certificate | `""` | +| Name | Description | Value | +| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------- | +| `certificate_authority_client_skip` | Skip creation or import of a client certificate in general. | `true` | +| `certificate_authority_client_create` | Create client certificate from scratch or import via `certificate_authority_client_tls` prefixed variables. | `true` | +| `certificate_authority_client_path` | Directory where the private and public TLS key of the client certificate authority should be stored. | `/etc/ansible-playbook/pki/client` | +| `certificate_authority_client_common_name` | Common Name (CN) of the client certificate. | `Ansible Client Certificate` | +| `certificate_authority_client_country_name` | Country name of the client certificate. For example `US`, `FR` or `DE`. | `""` | +| `certificate_authority_client_email_address` | E-Mail Address of the client certificate owner. | `""` | +| `certificate_authority_client_organization_name` | Organization name of the client certificate owner. | `""` | +| `certificate_authority_client_organizational_unit_name` | Organizational unit name of the client certificate. | `""` | +| `certificate_authority_client_state_or_province_name` | State or province name where the owner of the client certificate is located. | `""` | +| `certificate_authority_client_subject_alternative_names` | Subject Alternative Names (SAN) of the client certificate. Example: `DNS:example.local`, `IP:10.11.12.13`. | `[]` | +| `certificate_authority_client_not_after` | Time in the future from now when the TLS certificate should expire | `+397d` | +| `certificate_authority_client_not_before` | Time in the past from now when the TLS certificate should be valid. | `+0s` | +| `certificate_authority_client_tls_key_passphrase` | Passphrase for the private key of the generated or imported client certificate. | `""` | +| `certificate_authority_client_tls_key_type` | Algorithm of the private key of the client certificate. | `RSA` | +| `certificate_authority_client_tls_crt_content` | Content of a custom used client certificate. Will only be imported, when `certificate_authority_client_create: false`. | `""` | +| `certificate_authority_client_tls_key_content` | Content of the private key of a custom used client certificate. Will only be imported, when `certificate_authority_client_create: false`. | `""` | diff --git a/defaults/main.yaml b/defaults/main.yaml index 050d940..05a46cb 100644 --- a/defaults/main.yaml +++ b/defaults/main.yaml @@ -10,7 +10,7 @@ certificate_authority_root_ca_import: true ## @param certificate_authority_root_ca_path Directory where the private and public TLS key of the root certificate authority should be stored. ## @param certificate_authority_root_ca_common_name Common Name (CN) of the root certificate authority. -## @param certificate_authority_root_ca_country_name Common Name (CN) of the root certificate authority. For example `US`, `FR` or `DE`. +## @param certificate_authority_root_ca_country_name Country name of the root certificate authority. For example `US`, `FR` or `DE`. ## @param certificate_authority_root_ca_email_address E-Mail Address of the root certificate authority owner. ## @param certificate_authority_root_ca_organization_name Organization name of the root certificate authority owner. ## @param certificate_authority_root_ca_organizational_unit_name Organizational unit name of the root certificate authority. @@ -86,10 +86,10 @@ certificate_authority_client_create: true ## @param certificate_authority_client_path Directory where the private and public TLS key of the client certificate authority should be stored. ## @param certificate_authority_client_common_name Common Name (CN) of the client certificate. -## @param certificate_authority_client_country_name Country Name (CN) of the client certificate. For example `US`, `FR` or `DE`. +## @param certificate_authority_client_country_name Country name of the client certificate. For example `US`, `FR` or `DE`. ## @param certificate_authority_client_email_address E-Mail Address of the client certificate owner. ## @param certificate_authority_client_organization_name Organization name of the client certificate owner. -## @param certificate_authority_client_organizational_unit_name Common Name (CN) of the client certificate. +## @param certificate_authority_client_organizational_unit_name Organizational unit name of the client certificate. ## @param certificate_authority_client_state_or_province_name State or province name where the owner of the client certificate is located. ## @param certificate_authority_client_subject_alternative_names Subject Alternative Names (SAN) of the client certificate. Example: `DNS:example.local`, `IP:10.11.12.13`. ## @param certificate_authority_client_not_after Time in the future from now when the TLS certificate should expire @@ -110,7 +110,7 @@ certificate_authority_client_not_before: "+0s" certificate_authority_client_tls_key_passphrase: "" certificate_authority_client_tls_key_type: "RSA" -## @param certificate_authority_client_tls_crt_content Passphrase for the private key of the generated or imported client certificate. -## @param certificate_authority_client_tls_key_content Algorithm of the private key of the client certificate +## @param certificate_authority_client_tls_crt_content Content of a custom used client certificate. Will only be imported, when `certificate_authority_client_create: false`. +## @param certificate_authority_client_tls_key_content Content of the private key of a custom used client certificate. Will only be imported, when `certificate_authority_client_create: false`. certificate_authority_client_tls_crt_content: "" certificate_authority_client_tls_key_content: "" diff --git a/meta/argument_specs.yaml b/meta/argument_specs.yaml index afac55e..7c2d5b8 100644 --- a/meta/argument_specs.yaml +++ b/meta/argument_specs.yaml @@ -29,7 +29,7 @@ argument_specs: type: str default: "Ansible Root CA" certificate_authority_root_ca_country_name: - description: "Common Name (CN) of the root certificate authority. For example US, FR or DE." + description: "Country name of the root certificate authority. For example US, FR or DE." type: str default: "" certificate_authority_root_ca_email_address: @@ -173,7 +173,7 @@ argument_specs: type: str default: "Ansible Client Certificate" certificate_authority_client_country_name: - description: "Country Name (CN) of the client certificate. For example US, FR or DE." + description: "Country name of the client certificate. For example US, FR or DE." type: str default: "" certificate_authority_client_email_address: @@ -185,7 +185,7 @@ argument_specs: type: str default: "" certificate_authority_client_organizational_unit_name: - description: "Common Name (CN) of the client certificate." + description: "Organizational unit name of the client certificate." type: str default: "" certificate_authority_client_state_or_province_name: @@ -219,10 +219,10 @@ argument_specs: - DSA - ECC certificate_authority_client_tls_crt_content: - description: "Passphrase for the private key of the generated or imported client certificate." + description: "Content of a custom used client certificate. Will only be imported, when certificate_authority_client_create: false." type: str default: "" certificate_authority_client_tls_key_content: - description: "Algorithm of the private key of the client certificate" + description: "Content of the private key of a custom used client certificate. Will only be imported, when certificate_authority_client_create: false." type: str default: "" diff --git a/meta/main.yaml b/meta/main.yaml index 790dd7d..01afe76 100644 --- a/meta/main.yaml +++ b/meta/main.yaml @@ -2,7 +2,7 @@ dependencies: [] galaxy_info: author: "Markus Pesch" company: "Cryptic Systems" - description: "Role to create and managed an existing PKI infrastructure" + description: "Role to create and manage an existing PKI infrastructure" galaxy_tags: - ca - ssl diff --git a/package.json b/package.json index b50e0e4..90e1781 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "certificate-authority-ansible-role", - "homepage": "https://git.cryptic.systems/volker.raschel/certificate-authority-ansible-role.git", + "homepage": "https://git.cryptic.systems/volker.raschek/certificate-authority-ansible-role.git", "license": "MIT", "private": true, "engineStrict": true,