generate_pems.yaml 1.4 KB

12345678910111213141516171819202122232425262728293031323334353637
  1. ---
  2. - name: Checking for {{component}}.key
  3. stat: path="{{generated_certs_dir}}/{{component}}.key"
  4. register: key_file
  5. check_mode: no
  6. - name: Checking for {{component}}.crt
  7. stat: path="{{generated_certs_dir}}/{{component}}.crt"
  8. register: cert_file
  9. check_mode: no
  10. - name: Creating cert req for {{component}}
  11. command: >
  12. openssl req -out {{generated_certs_dir}}/{{component}}.csr -new -newkey rsa:2048 -keyout {{generated_certs_dir}}/{{component}}.key
  13. -subj "/CN={{component}}/OU=OpenShift/O=Logging/subjectAltName=DNS.1=localhost{{cert_ext.stdout}}" -days 712 -nodes
  14. when:
  15. - not key_file.stat.exists
  16. - cert_ext is defined
  17. - cert_ext.stdout is defined
  18. check_mode: no
  19. - name: Creating cert req for {{component}}
  20. command: >
  21. openssl req -out {{generated_certs_dir}}/{{component}}.csr -new -newkey rsa:2048 -keyout {{generated_certs_dir}}/{{component}}.key
  22. -subj "/CN={{component}}/OU=OpenShift/O=Logging" -days 712 -nodes
  23. when:
  24. - not key_file.stat.exists
  25. - cert_ext is undefined or cert_ext is defined and cert_ext.stdout is undefined
  26. check_mode: no
  27. - name: Sign cert request with CA for {{component}}
  28. command: >
  29. openssl ca -in {{generated_certs_dir}}/{{component}}.csr -notext -out {{generated_certs_dir}}/{{component}}.crt
  30. -config {{generated_certs_dir}}/signing.conf -extensions v3_req -batch -extensions server_ext
  31. when:
  32. - not cert_file.stat.exists
  33. check_mode: no