generate_pems.yaml 1.3 KB

123456789101112131415161718192021222324252627282930313233343536
  1. ---
  2. - name: Checking for {{component}}.key
  3. stat: path="{{generated_certs_dir}}/{{component}}.key"
  4. register: key_file
  5. check_mode: no
  6. - name: Checking for {{component}}.crt
  7. stat: path="{{generated_certs_dir}}/{{component}}.crt"
  8. register: cert_file
  9. check_mode: no
  10. - name: Creating cert req for {{component}}
  11. command: >
  12. openssl req -out {{generated_certs_dir}}/{{component}}.csr -new -newkey rsa:2048 -keyout {{generated_certs_dir}}/{{component}}.key
  13. -subj "/CN={{component}}/OU=OpenShift/O=Logging/subjectAltName=DNS.1=localhost{{cert_ext.stdout}}" -days 712 -nodes
  14. when:
  15. - not key_file.stat.exists
  16. - cert_ext.stdout is defined
  17. check_mode: no
  18. - name: Creating cert req for {{component}}
  19. command: >
  20. openssl req -out {{generated_certs_dir}}/{{component}}.csr -new -newkey rsa:2048 -keyout {{generated_certs_dir}}/{{component}}.key
  21. -subj "/CN={{component}}/OU=OpenShift/O=Logging" -days 712 -nodes
  22. when:
  23. - not key_file.stat.exists
  24. - cert_ext.stdout is undefined
  25. check_mode: no
  26. - name: Sign cert request with CA for {{component}}
  27. command: >
  28. openssl ca -in {{generated_certs_dir}}/{{component}}.csr -notext -out {{generated_certs_dir}}/{{component}}.crt
  29. -config {{generated_certs_dir}}/signing.conf -extensions v3_req -batch -extensions server_ext
  30. when:
  31. - not cert_file.stat.exists
  32. check_mode: no