Deploy the 2fa VPN certs

This commit is contained in:
Patrick Uiterwijk 2014-12-19 14:08:57 +00:00
parent e3a6a3d612
commit c6df88306c

View file

@ -188,10 +188,10 @@
# vpn certs # vpn certs
- name: copy server cert file over - name: copy VPN server cert file over
copy: > copy: >
src={{ puppet_private }}/2fa-certs/keys/fas-all.phx2.fedoraproject.org.crt src={{ puppet_private }}/2fa-certs/keys/fas-all.vpn.fedoraproject.org.crt
dest=/etc/pki/totpcgi/totpcgi-server.crt dest=/etc/pki/totpcgi/totpcgi-server-vpn.crt
owner=root owner=root
group=totpcgi group=totpcgi
mode=0640 mode=0640
@ -200,10 +200,10 @@
- config - config
when: env == "production" when: env == "production"
- name: copy server cert file over - name: copy VPN server cert file over
copy: > copy: >
src={{ puppet_private }}/2fa-certs/keys/fas-all.phx2.fedoraproject.org.key src={{ puppet_private }}/2fa-certs/keys/fas-all.vpn.fedoraproject.org.key
dest=/etc/pki/totpcgi/totpcgi-server.key dest=/etc/pki/totpcgi/totpcgi-server-vpn.key
owner=root owner=root
group=totpcgi group=totpcgi
mode=0640 mode=0640
@ -212,10 +212,10 @@
- config - config
when: env == "production" when: env == "production"
- name: copy server cert file over - name: copy VPN server cert file over
copy: > copy: >
src=totpcgi-httpd.conf src=totpcgi-httpd.conf.vpn
dest=/etc/httpd/conf.d/totpcgi.conf dest=/etc/httpd/conf.d/totpcgi-vpn.conf
owner=root owner=root
group=root group=root
mode=0444 mode=0444
@ -223,9 +223,6 @@
- files - files
- config - config
when: env == "production" when: env == "production"
#
# TODO: vpn certs
#
- name: copy ca cert over - name: copy ca cert over
copy: > copy: >