updated acme state

This commit is contained in:
Paul 2022-10-23 16:39:33 +02:00
parent 57b7bc9b32
commit 5685a34fe3
2 changed files with 4 additions and 2 deletions

View File

@ -25,6 +25,7 @@ def fetched(name=None,
currentcert = __salt__['pki.get_file_content'](checkfile=certfile) currentcert = __salt__['pki.get_file_content'](checkfile=certfile)
currentkey = __salt__['pki.get_file_content'](checkfile=keyfile) currentkey = __salt__['pki.get_file_content'](checkfile=keyfile)
currentfullcert = __salt__['pki.get_file_content'](checkfile=fullcertfile)
newcert, newkey = __salt__['pki.get_pki_cert'](url=url, newcert, newkey = __salt__['pki.get_pki_cert'](url=url,
username=username, username=username,
@ -32,8 +33,8 @@ def fetched(name=None,
domains=domain_concat) domains=domain_concat)
newfullcert = f"{newcert}\n\n{newkey}" newfullcert = f"{newcert}\n\n{newkey}"
if all([newcert,newkey]): if all([newcert,newkey,newfullcert]):
if currentcert != newcert or currentkey != newkey: if currentcert != newcert or currentkey != newkey != currentfullcert != newfullcert:
wcert = __salt__['pki.write_file_content'](newcert, certfile) wcert = __salt__['pki.write_file_content'](newcert, certfile)
wkey = __salt__['pki.write_file_content'](newkey, keyfile) wkey = __salt__['pki.write_file_content'](newkey, keyfile)
wfullcert = __salt__['pki.write_file_content'](newfullcert, fullcertfile) wfullcert = __salt__['pki.write_file_content'](newfullcert, fullcertfile)

View File

@ -5,6 +5,7 @@ acme:
- "/etc/acme/dh/" - "/etc/acme/dh/"
- "/etc/acme/keys/" - "/etc/acme/keys/"
- "/etc/acme/certs/" - "/etc/acme/certs/"
- "/etc/acme/fullchains/"
dh: dh:
path: "/etc/acme/dh/dh.pem" path: "/etc/acme/dh/dh.pem"
keysize: 2048 keysize: 2048