change cnf
This commit is contained in:
@@ -79,7 +79,7 @@
|
|||||||
|
|
||||||
- name: Generate server csr
|
- name: Generate server csr
|
||||||
ansible.builtin.shell:
|
ansible.builtin.shell:
|
||||||
cmd: 'openssl req -key {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.key -new -out {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.csr -config {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.cnf -days 365'
|
cmd: 'openssl req -key {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.key -new -out {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.csr -config {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.cnf'
|
||||||
|
|
||||||
- name: Sign server certificate
|
- name: Sign server certificate
|
||||||
ansible.builtin.shell:
|
ansible.builtin.shell:
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
[ req ]
|
|
||||||
prompt = no
|
prompt = no
|
||||||
days = 365
|
days = 365
|
||||||
distinguished_name = {{ rproxy_service_name }}.{{ domain.stdout }}
|
distinguished_name = {{ rproxy_service_name }}.{{ domain.stdout }}
|
||||||
@@ -15,10 +14,10 @@ commonName = {{ rproxy_service_name }}.{{ domain.stdout }}
|
|||||||
emailAddress = admin@{{ domain.stdout }}
|
emailAddress = admin@{{ domain.stdout }}
|
||||||
|
|
||||||
[ v3_req ]
|
[ v3_req ]
|
||||||
basicConstraints = CA:false
|
basicConstraints = critical; CA:false
|
||||||
extendedKeyUsage = serverAuth
|
extendedKeyUsage = serverAuth
|
||||||
subjectAltName = @sans
|
subjectAltName = @sans
|
||||||
|
|
||||||
[sans]
|
[ sans ]
|
||||||
DNS.1 = *.{{ domain.stdout }}
|
DNS.1 = *.{{ domain.stdout }}
|
||||||
IP.1 = {{ rproxy_service_address }}
|
IP.1 = {{ rproxy_service_address }}
|
||||||
24
server.cnf.j2
Normal file
24
server.cnf.j2
Normal file
@@ -0,0 +1,24 @@
|
|||||||
|
[ req ]
|
||||||
|
prompt = no
|
||||||
|
days = 365
|
||||||
|
distinguished_name = {{ rproxy_service_name }}.{{ domain.stdout }}
|
||||||
|
req_extensions = v3_req
|
||||||
|
|
||||||
|
|
||||||
|
[ {{ rproxy_service_name }}.{{ domain.stdout }} ]
|
||||||
|
countryName = RU
|
||||||
|
stateOrProvinceName = RU
|
||||||
|
localityName = MSK
|
||||||
|
organizationName = {{ domain.stdout }}
|
||||||
|
organizationalUnitName = IT
|
||||||
|
commonName = {{ rproxy_service_name }}.{{ domain.stdout }}
|
||||||
|
emailAddress = admin@{{ domain.stdout }}
|
||||||
|
|
||||||
|
[ v3_req ]
|
||||||
|
basicConstraints = CA:false
|
||||||
|
extendedKeyUsage = serverAuth
|
||||||
|
subjectAltName = @sans
|
||||||
|
|
||||||
|
[sans]
|
||||||
|
DNS.1 = *.{{ domain.stdout }}
|
||||||
|
IP.1 = {{ rproxy_service_address }}
|
||||||
Reference in New Issue
Block a user