Add sigul configuration for autosign
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
This commit is contained in:
parent
bd18812341
commit
1b4e469a96
2 changed files with 26 additions and 0 deletions
20
roles/robosignatory/files/sigul.production.conf
Normal file
20
roles/robosignatory/files/sigul.production.conf
Normal file
|
@ -0,0 +1,20 @@
|
|||
[client]
|
||||
bridge-hostname: sign-bridge1
|
||||
server-hostname: sign-vault1
|
||||
client-cert-nickname: sigul-client-cert
|
||||
user-name: autopen
|
||||
|
||||
[koji]
|
||||
koji-config: /etc/sigul/koji.conf
|
||||
koji-instances: primary
|
||||
koji-config-primary: /etc/sigul/koji.conf
|
||||
|
||||
[nss]
|
||||
nss-dir: /etc/sigul
|
||||
nss-password:
|
||||
nss-min-tls: tls1.2
|
||||
nss-max-tls: tls1.2
|
||||
|
||||
[binding]
|
||||
enabled: tpm
|
||||
tpm_nosrk: true
|
|
@ -20,6 +20,12 @@
|
|||
- config
|
||||
- robosignatory
|
||||
|
||||
- name: Install sigul configuration
|
||||
copy: src=sigul.{{env}}.conf dest=/etc/sigul/client.conf owner=fedmsg group=fedmsg mode=0640
|
||||
tags:
|
||||
- config
|
||||
- robosignatory
|
||||
|
||||
- name: Install koji certificate and key
|
||||
copy: src="{{ private }}/files/koji/autopen.pem" dest=/etc/robosignatory/koji.cert
|
||||
owner=fedmsg group=fedmsg mode=0640
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue