- minions: '{{ signing_policy.minions }}' | - minions: '{{ signing_policy.minions }}' | ||||
- signing_private_key: /etc/pki/ca/{{ ca_name }}/ca.key | - signing_private_key: /etc/pki/ca/{{ ca_name }}/ca.key | ||||
- signing_cert: /etc/pki/ca/{{ ca_name }}/ca.crt | - signing_cert: /etc/pki/ca/{{ ca_name }}/ca.crt | ||||
{%- if ca.country is defined %} | |||||
- C: {{ ca.country }} | - C: {{ ca.country }} | ||||
{%- endif %} | |||||
{%- if ca.state is defined %} | |||||
- ST: {{ ca.state }} | - ST: {{ ca.state }} | ||||
{%- endif %} | |||||
{%- if ca.locality is defined %} | |||||
- L: {{ ca.locality }} | - L: {{ ca.locality }} | ||||
{%- endif %} | |||||
{%- if ca.organization is defined %} | |||||
- O: {{ ca.organization }} | |||||
{%- endif %} | |||||
{%- if ca.organization_unit is defined %} | |||||
- OU: {{ ca.organization_unit }} | |||||
{%- endif %} | |||||
{%- if signing_policy.type == 'v3_edge_cert_client' %} | {%- if signing_policy.type == 'v3_edge_cert_client' %} | ||||
- basicConstraints: "CA:FALSE" | - basicConstraints: "CA:FALSE" | ||||
- keyUsage: "critical digitalSignature,nonRepudiation,keyEncipherment" | - keyUsage: "critical digitalSignature,nonRepudiation,keyEncipherment" |
x509.certificate_managed: | x509.certificate_managed: | ||||
- signing_private_key: /etc/pki/ca/{{ ca_name }}/ca.key | - signing_private_key: /etc/pki/ca/{{ ca_name }}/ca.key | ||||
- CN: {{ ca.common_name }} | - CN: {{ ca.common_name }} | ||||
{%- if ca.country is defined %} | |||||
- C: {{ ca.country }} | - C: {{ ca.country }} | ||||
{%- endif %} | |||||
{%- if ca.state is defined %} | |||||
- ST: {{ ca.state }} | - ST: {{ ca.state }} | ||||
{%- endif %} | |||||
{%- if ca.locality is defined %} | |||||
- L: {{ ca.locality }} | - L: {{ ca.locality }} | ||||
{%- endif %} | |||||
{%- if ca.organization is defined %} | |||||
- O: {{ ca.organization }} | |||||
{%- endif %} | |||||
{%- if ca.organization_unit is defined %} | |||||
- OU: {{ ca.organization_unit }} | |||||
{%- endif %} | |||||
- basicConstraints: "critical,CA:TRUE" | - basicConstraints: "critical,CA:TRUE" | ||||
- keyUsage: "critical,cRLSign,keyCertSign" | - keyUsage: "critical,cRLSign,keyCertSign" | ||||
- subjectKeyIdentifier: hash | - subjectKeyIdentifier: hash |