change cnf
This commit is contained in:
@@ -79,7 +79,7 @@
|
||||
|
||||
- name: Generate server csr
|
||||
ansible.builtin.shell:
|
||||
cmd: 'openssl req -key {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.key -new -out {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.csr -config {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.cnf -days 365'
|
||||
cmd: 'openssl req -key {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.key -new -out {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.csr -config {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.cnf'
|
||||
|
||||
- name: Sign server certificate
|
||||
ansible.builtin.shell:
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
[ req ]
|
||||
prompt = no
|
||||
days = 365
|
||||
distinguished_name = {{ rproxy_service_name }}.{{ domain.stdout }}
|
||||
@@ -15,10 +14,10 @@ commonName = {{ rproxy_service_name }}.{{ domain.stdout }}
|
||||
emailAddress = admin@{{ domain.stdout }}
|
||||
|
||||
[ v3_req ]
|
||||
basicConstraints = CA:false
|
||||
basicConstraints = critical; CA:false
|
||||
extendedKeyUsage = serverAuth
|
||||
subjectAltName = @sans
|
||||
|
||||
[sans]
|
||||
[ sans ]
|
||||
DNS.1 = *.{{ domain.stdout }}
|
||||
IP.1 = {{ rproxy_service_address }}
|
||||
24
server.cnf.j2
Normal file
24
server.cnf.j2
Normal file
@@ -0,0 +1,24 @@
|
||||
[ req ]
|
||||
prompt = no
|
||||
days = 365
|
||||
distinguished_name = {{ rproxy_service_name }}.{{ domain.stdout }}
|
||||
req_extensions = v3_req
|
||||
|
||||
|
||||
[ {{ rproxy_service_name }}.{{ domain.stdout }} ]
|
||||
countryName = RU
|
||||
stateOrProvinceName = RU
|
||||
localityName = MSK
|
||||
organizationName = {{ domain.stdout }}
|
||||
organizationalUnitName = IT
|
||||
commonName = {{ rproxy_service_name }}.{{ domain.stdout }}
|
||||
emailAddress = admin@{{ domain.stdout }}
|
||||
|
||||
[ v3_req ]
|
||||
basicConstraints = CA:false
|
||||
extendedKeyUsage = serverAuth
|
||||
subjectAltName = @sans
|
||||
|
||||
[sans]
|
||||
DNS.1 = *.{{ domain.stdout }}
|
||||
IP.1 = {{ rproxy_service_address }}
|
||||
Reference in New Issue
Block a user