New version of salt-formula from Saltstack
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

8 yıl önce
8 yıl önce
1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768
  1. {%- from "salt/map.jinja" import minion with context %}
  2. {%- if minion.enabled %}
  3. include:
  4. - salt.minion.service
  5. /etc/salt/minion.d/_pki.conf:
  6. file.managed:
  7. - source: salt://salt/files/_pki.conf
  8. - template: jinja
  9. - require:
  10. - pkg: salt_minion_packages
  11. - watch_in:
  12. - service: salt_minion_service
  13. {%- for ca_name,ca in minion.ca.iteritems() %}
  14. /etc/pki/ca/{{ ca_name }}/certs:
  15. file.directory:
  16. - makedirs: true
  17. /etc/pki/ca/{{ ca_name }}/ca.key:
  18. x509.private_key_managed:
  19. - bits: 4096
  20. - backup: True
  21. - require:
  22. - file: /etc/pki/ca/{{ ca_name }}/certs
  23. /etc/pki/ca/{{ ca_name }}/ca.crt:
  24. x509.certificate_managed:
  25. - signing_private_key: /etc/pki/ca/{{ ca_name }}/ca.key
  26. - CN: {{ ca.common_name }}
  27. {%- if ca.country is defined %}
  28. - C: {{ ca.country }}
  29. {%- endif %}
  30. {%- if ca.state is defined %}
  31. - ST: {{ ca.state }}
  32. {%- endif %}
  33. {%- if ca.locality is defined %}
  34. - L: {{ ca.locality }}
  35. {%- endif %}
  36. {%- if ca.organization is defined %}
  37. - O: {{ ca.organization }}
  38. {%- endif %}
  39. {%- if ca.organization_unit is defined %}
  40. - OU: {{ ca.organization_unit }}
  41. {%- endif %}
  42. - basicConstraints: "critical,CA:TRUE"
  43. - keyUsage: "critical,cRLSign,keyCertSign"
  44. - subjectKeyIdentifier: hash
  45. - authorityKeyIdentifier: keyid,issuer:always
  46. - days_valid: {{ ca.days_valid.authority }}
  47. - days_remaining: 0
  48. - backup: True
  49. - require:
  50. - x509: /etc/pki/ca/{{ ca_name }}/ca.key
  51. mine.send:
  52. module.run:
  53. - func: x509.get_pem_entries
  54. - kwargs:
  55. glob_path: /etc/pki/ca/{{ ca_name }}/ca.crt
  56. - onchanges:
  57. - x509: /etc/pki/ca/{{ ca_name }}/ca.crt
  58. {%- endfor %}
  59. {%- endif %}