The role used .yaml while the molecule scenario used .yml, because molecule hard codes molecule.yml and has no fallback for the other extension. Aligning all files on .yml keeps the extension consistent across the repository and avoids surprises when a tool only supports one of both spellings. Co-authored-by: Copilot <copilot@github.com>
33 lines
1.7 KiB
YAML
33 lines
1.7 KiB
YAML
---
|
|
|
|
- name: Create private key for root CA
|
|
community.crypto.openssl_privatekey:
|
|
path: "{{ certificate_authority_root_ca_path }}/privkey.pem"
|
|
mode: "0600"
|
|
type: "{{ certificate_authority_root_ca_tls_key_type }}"
|
|
|
|
- name: Create a certificate signing request (CSR) for root CA
|
|
community.crypto.openssl_csr:
|
|
basic_constraints:
|
|
- "CA:TRUE"
|
|
common_name: "{{ certificate_authority_root_ca_common_name }}"
|
|
countryName: "{{ certificate_authority_root_ca_country_name }}"
|
|
email_address: "{{ certificate_authority_root_ca_email_address }}"
|
|
organization_name: "{{ certificate_authority_root_ca_organization_name }}"
|
|
organizational_unit_name: "{{ certificate_authority_root_ca_organizational_unit_name }}"
|
|
path: "{{ certificate_authority_root_ca_path }}/cert-req.pem"
|
|
privatekey_path: "{{ certificate_authority_root_ca_path }}/privkey.pem"
|
|
state_or_province_name: "{{ certificate_authority_root_ca_state_or_province_name }}"
|
|
subject_alt_name: "{{ certificate_authority_root_ca_subject_alternative_names if certificate_authority_root_ca_subject_alternative_names | length > 0 else omit }}"
|
|
use_common_name_for_san: false
|
|
|
|
- name: Create self-signed certificate for root CA
|
|
community.crypto.x509_certificate:
|
|
csr_path: "{{ certificate_authority_root_ca_path }}/cert-req.pem"
|
|
path: "{{ certificate_authority_root_ca_path }}/cert.pem"
|
|
privatekey_path: "{{ certificate_authority_root_ca_path }}/privkey.pem"
|
|
provider: selfsigned
|
|
selfsigned_not_after: "{{ certificate_authority_root_ca_not_after }}"
|
|
selfsigned_not_before: "{{ certificate_authority_root_ca_not_before }}"
|
|
notify: Update systems SSL/TLS trust store
|