--- - name: Create directory to store tls keys and certificates of the root CA ansible.builtin.file: path: "{{ certificate_authority_root_ca_path }}" owner: "root" group: "root" mode: "0755" state: "directory" - name: Create unprotected root Certificate Authority (CA) ansible.builtin.include_tasks: root_certificate_authority_unprotected.yaml when: certificate_authority_root_ca_create is defined and certificate_authority_root_ca_create and certificate_authority_root_ca_tls_key_passphrase is defined and certificate_authority_root_ca_tls_key_passphrase | length <= 0 - name: Create passphrase protected root Certificate Authority (CA) ansible.builtin.include_tasks: root_certificate_authority_protected.yaml when: certificate_authority_root_ca_create is defined and certificate_authority_root_ca_create and certificate_authority_root_ca_tls_key_passphrase is defined and certificate_authority_root_ca_tls_key_passphrase | length > 0 - name: Import protected root Certificate Authority (CA) ansible.builtin.include_tasks: root_certificate_authority_import.yaml when: certificate_authority_root_ca_create is defined and not certificate_authority_root_ca_create - name: Create symbolic link for signed root certificate ansible.builtin.file: src: "{{ certificate_authority_root_ca_path }}/cert.pem" dest: "{{ certificate_authority_root_ca_path }}/{{ item }}" state: link with_items: - ca.pem - chain.pem - fullchain.pem - name: Create file with private key and fullchain file of root Certificate Authority (CA) ansible.builtin.include_tasks: concatenate.yaml vars: _concat_sources: - "{{ certificate_authority_root_ca_path }}/privkey.pem" - "{{ certificate_authority_root_ca_path }}/fullchain.pem" _concat_dest: "{{ certificate_authority_root_ca_path }}/all.pem" _concat_mode: "0600" - name: Import certificate of root Certificate Authority (CA) into systems trust store vars: # Debian based distributions only consider anchors with the file extension crt. _trust_store_anchor: Archlinux: "/etc/ca-certificates/trust-source/anchors/{{ certificate_authority_root_ca_common_name | replace(' ', '_') }}.pem" Debian: "/usr/local/share/ca-certificates/{{ certificate_authority_root_ca_common_name | replace(' ', '_') }}.crt" RedHat: "/etc/pki/ca-trust/source/anchors/{{ certificate_authority_root_ca_common_name | replace(' ', '_') }}.pem" _trust_store_update_command: Archlinux: "/usr/bin/update-ca-trust" Debian: "/usr/sbin/update-ca-certificates" RedHat: "/usr/bin/update-ca-trust" when: certificate_authority_root_ca_import is defined and certificate_authority_root_ca_import block: - name: Create symolic link ansible.builtin.file: src: "{{ certificate_authority_root_ca_path }}/cert.pem" dest: "{{ _trust_store_anchor[ansible_facts['os_family']] }}" owner: root group: root state: link - name: Update systems SSL/TLS trust store ansible.builtin.command: cmd: "{{ _trust_store_update_command[ansible_facts['os_family']] }}" register: _update_ca_trust changed_when: _update_ca_trust.rc == 0 failed_when: _update_ca_trust.rc > 0