diff --git a/roles/copr/backend/files/lighttpd/lighttpd.conf b/roles/copr/backend/files/lighttpd/lighttpd.conf index 9dfe9e4736..04b1318e7d 100644 --- a/roles/copr/backend/files/lighttpd/lighttpd.conf +++ b/roles/copr/backend/files/lighttpd/lighttpd.conf @@ -453,8 +453,8 @@ server.upload-dirs = ( "/var/tmp" ) $SERVER["socket"] == ":443" { ssl.engine = "enable" - ssl.pemfile = "/etc/lighttpd/copr-be.fedoraproject.org.pem" - ssl.ca-file = "/etc/lighttpd/DigiCertCA.crt" + ssl.pemfile = "/etc/lighttpd/copr.fedorainfracloud.org.crt" + ssl.ca-file = "/etc/lighttpd/copr.fedorainfracloud.org.intermediate.crt" ssl.disable-client-renegotiation = "enable" ssl.use-sslv2 = "disable" ssl.use-sslv3 = "disable" diff --git a/roles/copr/backend/tasks/install_certs.yml b/roles/copr/backend/tasks/install_certs.yml index a71401c301..8b17315c45 100644 --- a/roles/copr/backend/tasks/install_certs.yml +++ b/roles/copr/backend/tasks/install_certs.yml @@ -1,17 +1,10 @@ - name: copy httpd ssl certificates copy: src="{{ private }}/files/httpd/{{ item }}" dest="/etc/lighttpd/{{ item }}" owner=root group=root mode=0600 with_items: - - copr-be.fedoraproject.org.key - - copr-be.fedoraproject.org.crt - - copr-be.fedoraproject.org.pem + - copr.fedoraproject.org.key + - copr.fedoraproject.org.crt + - copr.fedoraproject.org.intermediate.crt notify: - restart lighttpd tags: - config - -- name: copy httpd ssl certificates (CAcert) - copy: src="DigiCertCA.crt" dest="/etc/lighttpd/" owner=root group=root mode=0600 - tags: - - config - notify: - - restart lighttpd