4 Commits

View File

@@ -27,6 +27,17 @@
become_user: "{{ ansible_user }}" become_user: "{{ ansible_user }}"
ignore_errors: true ignore_errors: true
- name: Get all tracking certificates
ansible.builtin.shell:
cmd: ipa-getcert list | grep "ID" | awk '{print $NF}' | tr -d "'\|:"
register: tracking_list
- name: Remove certificates from IPA tracking
ansible.builtin.shell:
cmd: "ipa-getcert stop-tracking -i {{ item }}"
loop: "{{ tracking_list.stdout_lines }}"
ignore_errors: true
- name: Request certificate via ipa-getcert - name: Request certificate via ipa-getcert
ansible.builtin.command: > ansible.builtin.command: >
ipa-getcert request ipa-getcert request
@@ -36,8 +47,6 @@
-N CN={{ ansible_facts['hostname'] }}.{{ ansible_facts['domain'] }} -N CN={{ ansible_facts['hostname'] }}.{{ ansible_facts['domain'] }}
-F {{ rproxy_dir }}/certs/RootCA.crt -F {{ rproxy_dir }}/certs/RootCA.crt
# sudo ipa-getcert stop-tracking -i 20250813210258 if track already exists
- name: Wait for certificate to appear - name: Wait for certificate to appear
ansible.builtin.wait_for: ansible.builtin.wait_for:
path: "{{ rproxy_dir }}/certs/repo.crt" path: "{{ rproxy_dir }}/certs/repo.crt"