Revert "wildcard-2022.fedoraproject.org cert"

This reverts commit 57f0d4fdb6.

For an anoying reason, armv7 image builds come up with the time as 10
days ago, which makes this cert invalid. So, move back to the old cert
for a week or so and then switch to the new one again. ;(
This commit is contained in:
Kevin Fenzi 2022-01-31 12:39:49 -08:00
parent 99479542bd
commit 4430178b29
7 changed files with 13 additions and 17 deletions

View file

@ -254,10 +254,10 @@ virt_install_command_two_nic_unsafe: virt-install -n {{ inventory_hostname }} --
vpn: False vpn: False
# This is the wildcard certname for our proxies. It has a different name for # This is the wildcard certname for our proxies. It has a different name for
# the staging group and is used in the proxies.yml playbook. # the staging group and is used in the proxies.yml playbook.
wildcard_cert_name: wildcard-2022.fedoraproject.org wildcard_cert_name: wildcard-2020.fedoraproject.org
wildcard_crt_file: wildcard-2022.fedoraproject.org.cert wildcard_crt_file: wildcard-2020.fedoraproject.org.cert
wildcard_int_file: wildcard-2022.fedoraproject.org.intermediate.cert wildcard_int_file: wildcard-2020.fedoraproject.org.intermediate.cert
wildcard_key_file: wildcard-2022.fedoraproject.org.key wildcard_key_file: wildcard-2020.fedoraproject.org.key
# #
# say if we want the apache role dependency for mod_wsgi or not # say if we want the apache role dependency for mod_wsgi or not
# In some cases we want mod_wsgi and no apache (for python3 httpaio stuff) # In some cases we want mod_wsgi and no apache (for python3 httpaio stuff)

View file

@ -19,10 +19,6 @@
certname: wildcard-2020.fedoraproject.org certname: wildcard-2020.fedoraproject.org
SSLCertificateChainFile: wildcard-2020.fedoraproject.org.intermediate.cert SSLCertificateChainFile: wildcard-2020.fedoraproject.org.intermediate.cert
- role: httpd/certificate
certname: wildcard-2022.fedoraproject.org
SSLCertificateChainFile: wildcard-2022.fedoraproject.org.intermediate.cert
- role: httpd/certificate - role: httpd/certificate
certname: wildcard-2020.id.fedoraproject.org certname: wildcard-2020.id.fedoraproject.org
SSLCertificateChainFile: wildcard-2020.id.fedoraproject.org.intermediate.cert SSLCertificateChainFile: wildcard-2020.id.fedoraproject.org.intermediate.cert

View file

@ -918,7 +918,7 @@
- role: httpd/website - role: httpd/website
site_name: nagios.fedoraproject.org site_name: nagios.fedoraproject.org
server_aliases: [nagios.stg.fedoraproject.org] server_aliases: [nagios.stg.fedoraproject.org]
SSLCertificateChainFile: wildcard-2022.fedoraproject.org.intermediate.cert SSLCertificateChainFile: wildcard-2020.fedoraproject.org.intermediate.cert
sslonly: true sslonly: true
cert_name: "{{wildcard_cert_name}}" cert_name: "{{wildcard_cert_name}}"

View file

@ -56,13 +56,13 @@
- selinux - selinux
- name: Copy wildcard cert from puppet private - name: Copy wildcard cert from puppet private
copy: src="{{private}}/files/httpd/wildcard-2022.fedoraproject.org.cert" dest=/etc/pki/tls/certs/wildcard-2022.fedoraproject.org.cert owner=root group=root mode=0644 copy: src="{{private}}/files/httpd/wildcard-2020.fedoraproject.org.cert" dest=/etc/pki/tls/certs/wildcard-2020.fedoraproject.org.cert owner=root group=root mode=0644
- name: Copy wildcard key from puppet private - name: Copy wildcard key from puppet private
copy: src="{{private}}/files/httpd/wildcard-2022.fedoraproject.org.key" dest=/etc/pki/tls/private/wildcard-2022.fedoraproject.org.key owner=root group=root mode=0600 copy: src="{{private}}/files/httpd/wildcard-2020.fedoraproject.org.key" dest=/etc/pki/tls/private/wildcard-2020.fedoraproject.org.key owner=root group=root mode=0600
- name: Copy intermediate wildcard cert from puppet private - name: Copy intermediate wildcard cert from puppet private
copy: src="{{private}}/files/httpd/wildcard-2022.fedoraproject.org.intermediate.cert" dest=/etc/pki/tls/certs/wildcard-2022.fedoraproject.org.intermediate.cert owner=root group=root mode=0644 copy: src="{{private}}/files/httpd/wildcard-2020.fedoraproject.org.intermediate.cert" dest=/etc/pki/tls/certs/wildcard-2020.fedoraproject.org.intermediate.cert owner=root group=root mode=0644
- name: Configure httpd dl main conf - name: Configure httpd dl main conf
template: src=httpd/dl.fedoraproject.org.conf dest=/etc/httpd/conf.d/dl.fedoraproject.org.conf template: src=httpd/dl.fedoraproject.org.conf dest=/etc/httpd/conf.d/dl.fedoraproject.org.conf

View file

@ -98,8 +98,8 @@
- name: put our combined cert in place - name: put our combined cert in place
copy: > copy: >
src={{private}}/files/httpd/wildcard-2022.fedoraproject.org.combined.cert src={{private}}/files/httpd/wildcard-2020.fedoraproject.org.combined.cert
dest=/etc/pki/tls/certs/wildcard-2022.fedoraproject.org.combined.cert dest=/etc/pki/tls/certs/wildcard-2020.fedoraproject.org.combined.cert
owner=root group=root mode=0644 owner=root group=root mode=0644
notify: restart stunnel notify: restart stunnel
tags: tags:

View file

@ -1,5 +1,5 @@
cert = /etc/pki/tls/certs/wildcard-2022.fedoraproject.org.combined.cert cert = /etc/pki/tls/certs/wildcard-2020.fedoraproject.org.combined.cert
key = /etc/pki/tls/private/wildcard-2022.fedoraproject.org.key key = /etc/pki/tls/private/wildcard-2020.fedoraproject.org.key
pid = /var/run/stunnel.pid pid = /var/run/stunnel.pid
[{{ stunnel_service }}] [{{ stunnel_service }}]

View file

@ -8,7 +8,7 @@ server_admin: webmaster@fedoraproject.org
certbot: false certbot: false
ssl: true ssl: true
sslonly: false sslonly: false
SSLCertificateChainFile: wildcard-2022.fedoraproject.org.intermediate.cert SSLCertificateChainFile: wildcard-2020.fedoraproject.org.intermediate.cert
gzip: false gzip: false
stssubdomains: true stssubdomains: true
# set to true to enable the proxy to redirect the http01 challenge # set to true to enable the proxy to redirect the http01 challenge