Compare commits

..

No commits in common. "main" and "master" have entirely different histories.
main ... master

4 changed files with 19 additions and 14 deletions

View file

@ -4,3 +4,4 @@ selfsignedcert_suffix_csr: csr.pem
selfsignedcert_suffix_crt: crt.pem
selfsignedcert_suffix_combined: pem

View file

@ -4,3 +4,4 @@
roles:
- role: selfsignedcert
selfsignedcert_basename: ./example-cert

View file

@ -7,8 +7,9 @@ galaxy_info:
license: GPL-2.0-or-later
min_ansible_version: '2.10'
min_ansible_version: 2.9
galaxy_tags:
- certificate
- ssl

View file

@ -1,28 +1,28 @@
---
- name: Sanity checks
ansible.builtin.assert:
assert:
that:
- selfsignedcert_basename | default("") != ""
- selfsignedcert_basename|default("") != ""
- name: Generate private key
community.crypto.openssl_privatekey:
openssl_privatekey:
path: '{{ selfsignedcert_basename }}.{{ selfsignedcert_suffix_key }}'
size: '{{ selfsignedcert_keysize | default(2048) }}'
mode: '0600'
size: '{{ selfsignedcert_keysize|default(2048) }}'
mode: 0600
register: selfsignedcert_result_key
- name: Generate CSR
community.crypto.openssl_csr:
openssl_csr:
path: '{{ selfsignedcert_basename }}.{{ selfsignedcert_suffix_csr }}'
privatekey_path: '{{ selfsignedcert_basename }}.{{ selfsignedcert_suffix_key }}'
common_name: '{{ selfsigned_cn | default(ansible_hostname) }}'
subject_alt_name: '{{ selfsigned_san | default([]) }}'
common_name: '{{ selfsigned_cn|default(ansible_hostname) }}'
subject_alt_name: '{{ selfsigned_san|default([]) }}'
- name: Generate certificate
community.crypto.x509_certificate:
openssl_certificate:
path: '{{ selfsignedcert_basename }}.{{ selfsignedcert_suffix_crt }}'
privatekey_path: '{{ selfsignedcert_basename }}.{{ selfsignedcert_suffix_key }}'
csr_path: '{{ selfsignedcert_basename }}.{{ selfsignedcert_suffix_csr }}'
@ -31,9 +31,11 @@
- name: Combine key and certificate
ansible.builtin.template:
template:
src: combined.j2
dest: '{{ selfsignedcert_basename }}.{{ selfsignedcert_suffix_combined }}'
mode: '0600'
backup: true
when: not selfsignedcert_suffix_combined
mode: 0600
backup: yes
when: selfsignedcert_suffix_combined != False