Building chain.pem, fullchain.pem and all.pem was implemented seven times across three task files with identical stat, awk and copy tasks. The blocks now include tasks/concatenate.yaml and pass the sources, the destination and the mode, which removes about a hundred lines. Two side effects come with it. Every source file is checked instead of only the foreign one, so a missing file skips the block instead of letting awk fail. And the trailing newline of the result is kept, because stdout_lines joined by a newline dropped it. Co-authored-by: Copilot <copilot@github.com>
76 lines
3.2 KiB
YAML
76 lines
3.2 KiB
YAML
---
|
|
|
|
- name: Create directory to store tls keys and certificates of the root CA
|
|
ansible.builtin.file:
|
|
path: "{{ certificate_authority_root_ca_path }}"
|
|
owner: "root"
|
|
group: "root"
|
|
mode: "0755"
|
|
state: "directory"
|
|
|
|
- name: Create unprotected root Certificate Authority (CA)
|
|
ansible.builtin.include_tasks: root_certificate_authority_unprotected.yaml
|
|
when: certificate_authority_root_ca_create is defined and
|
|
certificate_authority_root_ca_create and
|
|
certificate_authority_root_ca_tls_key_passphrase is defined and
|
|
certificate_authority_root_ca_tls_key_passphrase | length <= 0
|
|
|
|
- name: Create passphrase protected root Certificate Authority (CA)
|
|
ansible.builtin.include_tasks: root_certificate_authority_protected.yaml
|
|
when: certificate_authority_root_ca_create is defined and
|
|
certificate_authority_root_ca_create and
|
|
certificate_authority_root_ca_tls_key_passphrase is defined and
|
|
certificate_authority_root_ca_tls_key_passphrase | length > 0
|
|
|
|
- name: Import protected root Certificate Authority (CA)
|
|
ansible.builtin.include_tasks: root_certificate_authority_import.yaml
|
|
when: certificate_authority_root_ca_create is defined and
|
|
not certificate_authority_root_ca_create
|
|
|
|
- name: Create symbolic link for signed root certificate
|
|
ansible.builtin.file:
|
|
src: "{{ certificate_authority_root_ca_path }}/cert.pem"
|
|
dest: "{{ certificate_authority_root_ca_path }}/{{ item }}"
|
|
state: link
|
|
with_items:
|
|
- ca.pem
|
|
- chain.pem
|
|
- fullchain.pem
|
|
|
|
- name: Create file with private key and fullchain file of root Certificate Authority (CA)
|
|
ansible.builtin.include_tasks: concatenate.yaml
|
|
vars:
|
|
_concat_sources:
|
|
- "{{ certificate_authority_root_ca_path }}/privkey.pem"
|
|
- "{{ certificate_authority_root_ca_path }}/fullchain.pem"
|
|
_concat_dest: "{{ certificate_authority_root_ca_path }}/all.pem"
|
|
_concat_mode: "0600"
|
|
|
|
- name: Import certificate of root Certificate Authority (CA) into systems trust store
|
|
vars:
|
|
# Debian based distributions only consider anchors with the file extension crt.
|
|
_trust_store_anchor:
|
|
Archlinux: "/etc/ca-certificates/trust-source/anchors/{{ certificate_authority_root_ca_common_name | replace(' ', '_') }}.pem"
|
|
Debian: "/usr/local/share/ca-certificates/{{ certificate_authority_root_ca_common_name | replace(' ', '_') }}.crt"
|
|
RedHat: "/etc/pki/ca-trust/source/anchors/{{ certificate_authority_root_ca_common_name | replace(' ', '_') }}.pem"
|
|
_trust_store_update_command:
|
|
Archlinux: "/usr/bin/update-ca-trust"
|
|
Debian: "/usr/sbin/update-ca-certificates"
|
|
RedHat: "/usr/bin/update-ca-trust"
|
|
when: certificate_authority_root_ca_import is defined and
|
|
certificate_authority_root_ca_import
|
|
block:
|
|
- name: Create symolic link
|
|
ansible.builtin.file:
|
|
src: "{{ certificate_authority_root_ca_path }}/cert.pem"
|
|
dest: "{{ _trust_store_anchor[ansible_facts['os_family']] }}"
|
|
owner: root
|
|
group: root
|
|
state: link
|
|
- name: Update systems SSL/TLS trust store
|
|
ansible.builtin.command:
|
|
cmd: "{{ _trust_store_update_command[ansible_facts['os_family']] }}"
|
|
register: _update_ca_trust
|
|
changed_when: _update_ca_trust.rc == 0
|
|
failed_when: _update_ca_trust.rc > 0
|