浏览代码

Add support for specifying dh_param file name

master
Gilles Dartiguelongue 7 年前
父节点
当前提交
d2bc1e6d7c
共有 2 个文件被更改,包括 19 次插入16 次删除
  1. +11
    -9
      nginx/ng/certificates.sls
  2. +8
    -7
      pillar.example

+ 11
- 9
nginx/ng/certificates.sls 查看文件

@@ -5,24 +5,26 @@ include:

{% set certificates_path = salt['pillar.get']('nginx:ng:certificates_path', '/etc/nginx/ssl') %}

{% if salt.pillar.get('nginx:ng:dh_contents') %}
create_nginx_dhparam_key:
{%- for dh_param, value in salt.pillar.get('nginx:ng:dh_param').items() %}
{%- if value is string %}
create_nginx_dhparam_{{ dh_param }}_key:
file.managed:
- name: {{ certificates_path }}/dhparam.pem
- contents_pillar: nginx:ng:dh_contents
- name: {{ certificates_path }}/{{ dh_param }}
- contents_pillar: nginx:ng:dh_param:{{ dh_param }}
- makedirs: True
{% elif salt.pillar.get('nginx:ng:dh_keygen', False) %}
generate_nginx_dhparam_key:
{%- else %}
generate_nginx_dhparam_{{ dh_param }}_key:
pkg.installed:
- name: {{ nginx.lookup.openssl_package }}
file.directory:
- name: {{ certificates_path }}
- makedirs: True
cmd.run:
- name: openssl dhparam -out dhparam.pem {{ salt.pillar.get('nginx:ng:dh_keysize', 2048) }}
- name: openssl dhparam -out {{ dh_param }} {{ value.get('keysize', 2048) }}
- cwd: {{ certificates_path }}
- creates: {{ certificates_path }}/dhparam.pem
{% endif %}
- creates: {{ certificates_path }}/{{ dh_param }}
{%- endif %}
{%- endfor %}

{%- for domain in salt['pillar.get']('nginx:ng:certificates', {}).keys() %}


+ 8
- 7
pillar.example 查看文件

@@ -153,13 +153,14 @@ nginx:
(Your Private Key: www.example.com.key)
-----END RSA PRIVATE KEY-----

dh_contents: |
-----BEGIN DH PARAMETERS-----
(Your custom DH prime)
-----END DH PARAMETERS-----
# or to generate one on-the-fly
dh_keygen: true
dh_keysize: 2048
dh_param:
'mydhparam1.pem': |
-----BEGIN DH PARAMETERS-----
(Your custom DH prime)
-----END DH PARAMETERS-----
# or to generate one on-the-fly
'mydhparam2.pem':
keysize: 2048

# Passenger configuration
# Default passenger configuration is provided, and will be deployed in

正在加载...
取消
保存