The variables `certificate_authority_root_ca_subject_alternative_names` and
`certificate_authority_intermediate_ca_subject_alternative_names` were
documented but never referenced by any task, so both CA certificates were always
issued without SANs. Wire them into the corresponding CSR tasks and fall back to
`omit` when the list is empty.
SAN entries are now passed to `openssl_csr` unchanged instead of being prefixed
with `DNS:` by the role. This allows other types such as `IP:` or `email:`,
which the previous rewrite would have corrupted into values like `DNS:IP:...`.
The client tasks additionally dropped `join(',') | quote`, because `quote`
performs shell escaping and `openssl_csr` expects a list.
Since both client CSR tasks only differed in `subject_alt_name`, they collapse
into a single task per file.
BREAKING CHANGE: Entries of all `*_subject_alternative_names` variables must now
carry their type prefix, for example `DNS:example.local` instead of
`example.local`.
Co-authored-by: Copilot <copilot@github.com>
14 KiB
14 KiB
certificate-authority
This Ansible role can be used to create a root and intermediate certificate authority and issue client certificates from them. Additionally offers the ansible role the feature to import the certificates of the authority into the systems trust store.
Examples
The following minimal example creates a root and intermediate certificate authority and issues a client certificate from the intermediate certificate authority.
certificate_authority_client_skip: false
certificate_authority_client_common_name: "{{ inventory_hostname }}"
certificate_authority_client_subject_alternative_names:
- "DNS:{{ inventory_hostname }}"
- "DNS:san.example.local"
- "IP:10.11.12.13"
Parameters
Root Certificate Authority (CA)
| Name | Description | Value |
|---|---|---|
certificate_authority_root_ca_skip |
Skip creation or import of a root certificate authority in general. | false |
certificate_authority_root_ca_create |
Create root certificate from scratch or import via certificate_authority_root_ca_tls prefixed variables. |
true |
certificate_authority_root_ca_import |
Import the TLS certificate of the root certificate authority into the systems trust store. | true |
certificate_authority_root_ca_path |
Directory where the private and public TLS key of the root certificate authority should be stored. | /etc/ansible-playbook/pki/ca |
certificate_authority_root_ca_common_name |
Common Name (CN) of the root certificate authority. | Ansible Root CA |
certificate_authority_root_ca_country_name |
Common Name (CN) of the root certificate authority. For example US, FR or DE. |
"" |
certificate_authority_root_ca_email_address |
E-Mail Address of the root certificate authority owner. | "" |
certificate_authority_root_ca_organization_name |
Organization name of the root certificate authority owner. | "" |
certificate_authority_root_ca_organizational_unit_name |
Organizational unit name of the root certificate authority. | "" |
certificate_authority_root_ca_state_or_province_name |
State or province name where the owner of the root certificate authority is located. | "" |
certificate_authority_root_ca_subject_alternative_names |
Subject Alternative Names (SAN) of the root certificate authority. Each entry must be prefixed by its type, for example DNS:example.local or IP:10.11.12.13. |
[] |
certificate_authority_root_ca_not_after |
Time in the future from now when the TLS certificate should expire | +3650d |
certificate_authority_root_ca_not_before |
Time in the past from now when the TLS certificate should be valid. | +0s |
certificate_authority_root_ca_tls_key_content |
Content of a custom used root certificate authority. Will only be imported, when certificate_authority_root_ca_create: false. |
"" |
certificate_authority_root_ca_tls_crt_content |
Content of a custom used certificate of the certificate authority. Will only be imported, when certificate_authority_root_ca_create: false. |
"" |
certificate_authority_root_ca_tls_key_passphrase |
Passphrase for the private key of the generated or imported root certificate authority. | "" |
certificate_authority_root_ca_tls_key_type |
Algorithm of the private key of the root certificate authority. | RSA |
Intermediate Certificate Authority (CA)
| Name | Description | Value |
|---|---|---|
certificate_authority_intermediate_ca_skip |
Skip creation or import of a intermediate certificate authority in general. | false |
certificate_authority_intermediate_ca_create |
Create intermediate certificate from scratch or import via certificate_authority_intermediate_ca_tls prefixed variables. |
true |
certificate_authority_intermediate_ca_path |
Directory where the private and public TLS key of the intermediate certificate authority should be stored. | /etc/ansible-playbook/pki/intermediate |
certificate_authority_intermediate_ca_common_name |
Common Name (CN) of the intermediate certificate authority. | Ansible Intermediate CA |
certificate_authority_intermediate_ca_country_name |
Country name of the intermediate certificate authority. For example US, FR or DE. |
"" |
certificate_authority_intermediate_ca_email_address |
E-Mail Address of the intermediate certificate authority owner. | "" |
certificate_authority_intermediate_ca_organization_name |
Organization name of the intermediate certificate authority owner. | "" |
certificate_authority_intermediate_ca_organizational_unit_name |
Organizational unit name of the intermediate certificate authority. | "" |
certificate_authority_intermediate_ca_state_or_province_name |
State or province name where the owner of the intermediate certificate authority is located. | "" |
certificate_authority_intermediate_ca_subject_alternative_names |
Subject Alternative Names (SAN) of the intermediate certificate authority. Each entry must be prefixed by its type, for example DNS:example.local or IP:10.11.12.13. |
[] |
certificate_authority_intermediate_ca_not_after |
Time in the future from now when the TLS certificate should expire | +1825d |
certificate_authority_intermediate_ca_not_before |
Time in the past from now when the TLS certificate should be valid. | +0s |
certificate_authority_intermediate_ca_tls_key_content |
Content of a custom used intermediate certificate authority. Will only be imported, when certificate_authority_intermediate_ca_create: false. |
"" |
certificate_authority_intermediate_ca_tls_crt_content |
Content of a custom used certificate of the certificate authority. Will only be imported, when certificate_authority_intermediate_ca_create: false. |
"" |
certificate_authority_intermediate_ca_tls_key_passphrase |
Passphrase for the private key of the generated or imported intermediate certificate authority. | "" |
certificate_authority_intermediate_ca_tls_key_type |
Algorithm of the private key of the intermediate certificate authority. | RSA |
Client Certificate
| Name | Description | Value |
|---|---|---|
certificate_authority_client_skip |
Skip creation or import of a client certificate in general. | true |
certificate_authority_client_create |
Create client certificate from scratch or import via certificate_authority_client_tls prefixed variables. |
true |
certificate_authority_client_path |
Directory where the private and public TLS key of the client certificate authority should be stored. | /etc/ansible-playbook/pki/client |
certificate_authority_client_common_name |
Common Name (CN) of the client certificate. | Ansible Client Certificate |
certificate_authority_client_country_name |
Country Name (CN) of the client certificate. For example US, FR or DE. |
"" |
certificate_authority_client_email_address |
E-Mail Address of the client certificate owner. | "" |
certificate_authority_client_organization_name |
Organization name of the client certificate owner. | "" |
certificate_authority_client_organizational_unit_name |
Common Name (CN) of the client certificate. | "" |
certificate_authority_client_state_or_province_name |
State or province name where the owner of the client certificate is located. | "" |
certificate_authority_client_subject_alternative_names |
Subject Alternative Names (SAN) of the client certificate. Each entry must be prefixed by its type, for example DNS:example.local or IP:10.11.12.13. |
[] |
certificate_authority_client_not_after |
Time in the future from now when the TLS certificate should expire | +397d |
certificate_authority_client_not_before |
Time in the past from now when the TLS certificate should be valid. | +0s |
certificate_authority_client_tls_key_passphrase |
Passphrase for the private key of the generated or imported client certificate. | "" |
certificate_authority_client_tls_key_type |
Algorithm of the private key of the client certificate. | RSA |
certificate_authority_client_tls_crt_content |
Passphrase for the private key of the generated or imported client certificate. | "" |
certificate_authority_client_tls_key_content |
Algorithm of the private key of the client certificate | "" |