dev #3

Merged
mpavlov merged 28 commits from dev into master 2024-07-11 01:21:55 +03:00
8 changed files with 219 additions and 60 deletions
Showing only changes of commit 17bb4d1271 - Show all commits

View File

@@ -83,7 +83,7 @@
- name: Sign server certificate - name: Sign server certificate
ansible.builtin.shell: ansible.builtin.shell:
cmd: 'openssl x509 -req -CA {{ rproxy_dir }}/certs/RootCA.crt -CAkey {{ rproxy_dir }}/certs/RootCA.key -in {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.csr -out {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.crt -CAcreateserial -extfile {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.cnf' cmd: 'openssl x509 -req -CA {{ rproxy_dir }}/certs/RootCA.crt -CAkey {{ rproxy_dir }}/certs/RootCA.key -in {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.csr -out {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.crt -CAcreateserial -config {{ rproxy_dir }}/certs/{{ rproxy_service_name }}.cnf -days 365'
- name: Create fullchain certificate - name: Create fullchain certificate
ansible.builtin.shell: ansible.builtin.shell:

View File

@@ -1,8 +1,8 @@
[ req ] [ req ]
prompt = no prompt = no
days = 365
distinguished_name = {{ rproxy_service_name }}.{{ domain.stdout }} distinguished_name = {{ rproxy_service_name }}.{{ domain.stdout }}
req_extensions = v3_req req_extensions = v3_req
x509_extensions = v3_x509
[ {{ rproxy_service_name }}.{{ domain.stdout }} ] [ {{ rproxy_service_name }}.{{ domain.stdout }} ]
@@ -16,9 +16,14 @@ emailAddress = admin@{{ domain.stdout }}
[ v3_req ] [ v3_req ]
basicConstraints = CA:false basicConstraints = CA:false
keyUsage = digitalSignature, keyEncipherment keyUsage = digitalSignature, keyEncipherment
subjectAltName = @sans
[ v3_x509 ]
basicConstraints = CA:false
keyUsage = digitalSignature, keyEncipherment
subjectAltName = @sans subjectAltName = @sans
[ sans ] [ sans ]
DNS.1 = *.{{ domain.stdout }} DNS.1 = {{ rproxy_service_name }}.{{ domain.stdout }}
IP.1 = {{ rproxy_service_address }} IP.1 = {{ rproxy_service_address }}