Enable DNS over TLS support for local resolvers
Currently uses local CA.
This commit is contained in:
parent
581484d207
commit
8bdf278ea6
4 changed files with 31 additions and 4 deletions
|
@ -70,6 +70,24 @@
|
|||
owner: root
|
||||
group: "{{ ansible_wheel }}"
|
||||
|
||||
- name: copy dns private key
|
||||
copy:
|
||||
dest: "{{ tls_private }}/dns.home.foo.sh.key"
|
||||
src: /srv/ca/private/dns.home.foo.sh.key
|
||||
mode: 0600
|
||||
owner: root
|
||||
group: "{{ ansible_wheel }}"
|
||||
tags: certificate
|
||||
notify: restart unbound
|
||||
- name: copy dns certificate and ca cert
|
||||
copy:
|
||||
dest: "{{ tls_certs }}/dns.home.foo.sh.crt"
|
||||
src: /srv/ca/certs/dns.home.foo.sh.crt
|
||||
mode: 0644
|
||||
owner: root
|
||||
group: "{{ ansible_wheel }}"
|
||||
tags: certificate
|
||||
notify: restart unbound
|
||||
- name: copy dns zone files
|
||||
copy:
|
||||
dest: "/var/unbound/db/{{ item }}"
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue