Re organized internal CA directories

This commit is contained in:
Timo Makinen 2021-10-07 18:03:05 +00:00
parent ee39a34fad
commit 7a2b2c0b48
6 changed files with 9 additions and 9 deletions

View file

@ -36,7 +36,7 @@
group: "{{ ansible_wheel }}"
with_first_found:
- "/srv/letsencrypt/live/{{ mail_server }}/fullchain.pem"
- "/srv/ca/certs/{{ inventory_hostname }}.crt"
- "/srv/ca/certs/hosts/{{ inventory_hostname }}.crt"
tags: certificates
notify: restart dovecot

View file

@ -41,7 +41,7 @@
validate: /usr/bin/openssl x509 -in %s -noout
with_first_found:
- "/srv/letsencrypt/live/{{ site }}/fullchain.pem"
- "/srv/ca/certs/{{ site }}.crt"
- "/srv/ca/certs/{{ inventory_hostname }}.crt"
- "/srv/ca/certs/hosts/{{ site }}.crt"
- "/srv/ca/certs/hosts/{{ inventory_hostname }}.crt"
tags: certificates
notify: restart nginx

View file

@ -22,8 +22,8 @@
group: "{{ ansible_wheel }}"
with_first_found:
- "/srv/letsencrypt/live/{{ nsd_server }}/fullchain.pem"
- "/srv/ca/certs/{{ site }}.crt"
- "/srv/ca/certs/{{ inventory_hostname }}.crt"
- "/srv/ca/certs/hosts/{{ site }}.crt"
- "/srv/ca/certs/hosts/{{ inventory_hostname }}.crt"
tags: certificates
notify: restart nsd

View file

@ -24,7 +24,7 @@
- name: copy host certificate
copy:
src: "/srv/ca/certs/{{ inventory_hostname }}.crt"
src: "/srv/ca/certs/hosts/{{ inventory_hostname }}.crt"
dest: "{{ tls_certs }}/{{ inventory_hostname }}.crt"
mode: 0644
owner: root

View file

@ -41,8 +41,8 @@
validate: /usr/bin/openssl x509 -in %s -noout
with_first_found:
- "/srv/letsencrypt/live/{{ mail_server }}/cert.pem"
- "/srv/ca/certs/{{ mail_server }}.crt"
- "/srv/ca/certs/{{ inventory_hostname }}.crt"
- "/srv/ca/certs/hosts/{{ mail_server }}.crt"
- "/srv/ca/certs/hosts/{{ inventory_hostname }}.crt"
tags: certificates
notify: restart sendmail

View file

@ -70,7 +70,7 @@
group: "{{ ansible_wheel }}"
with_first_found:
- "/srv/letsencrypt/live/{{ inventory_hostname }}/privkey.pem"
- "/srv/ca/certs/{{ inventory_hostname }}.key"
- "/srv/ca/certs/hosts/{{ inventory_hostname }}.key"
tags: certificates
notify: restart tlwebaccess