The RabbitMQ ansible modules can't use https yet.

Disable SSL on the management api, and mitigate the security risk by
only listening on localhost.
This commit is contained in:
Aurélien Bompard 2018-10-05 09:40:57 +00:00
parent 8dad9ed1de
commit e90ec28ebe

View file

@ -31,10 +31,13 @@
{rabbitmq_management, {rabbitmq_management,
[ [
{listener, [{port, 15672}, {listener, [{port, 15672},
{ssl, true}, {ip, "127.0.0.1"}
{ssl_opts, [{cacertfile, "/etc/rabbitmq/ca.crt"}, # Ansible can't use HTTPS yet
{certfile, "/etc/rabbitmq/nodecert/node.crt"}, #{ssl, true},
{keyfile, "/etc/rabbitmq/nodecert/node.key"}]}]} #{ssl_opts, [{cacertfile, "/etc/rabbitmq/ca.crt"},
# {certfile, "/etc/rabbitmq/nodecert/node.crt"},
# {keyfile, "/etc/rabbitmq/nodecert/node.key"}]}
]}
]}, ]},
{rabbitmq_management_agent, {rabbitmq_management_agent,