updated acme state
This commit is contained in:
parent
57b7bc9b32
commit
5685a34fe3
@ -25,6 +25,7 @@ def fetched(name=None,
|
|||||||
|
|
||||||
currentcert = __salt__['pki.get_file_content'](checkfile=certfile)
|
currentcert = __salt__['pki.get_file_content'](checkfile=certfile)
|
||||||
currentkey = __salt__['pki.get_file_content'](checkfile=keyfile)
|
currentkey = __salt__['pki.get_file_content'](checkfile=keyfile)
|
||||||
|
currentfullcert = __salt__['pki.get_file_content'](checkfile=fullcertfile)
|
||||||
|
|
||||||
newcert, newkey = __salt__['pki.get_pki_cert'](url=url,
|
newcert, newkey = __salt__['pki.get_pki_cert'](url=url,
|
||||||
username=username,
|
username=username,
|
||||||
@ -32,8 +33,8 @@ def fetched(name=None,
|
|||||||
domains=domain_concat)
|
domains=domain_concat)
|
||||||
newfullcert = f"{newcert}\n\n{newkey}"
|
newfullcert = f"{newcert}\n\n{newkey}"
|
||||||
|
|
||||||
if all([newcert,newkey]):
|
if all([newcert,newkey,newfullcert]):
|
||||||
if currentcert != newcert or currentkey != newkey:
|
if currentcert != newcert or currentkey != newkey != currentfullcert != newfullcert:
|
||||||
wcert = __salt__['pki.write_file_content'](newcert, certfile)
|
wcert = __salt__['pki.write_file_content'](newcert, certfile)
|
||||||
wkey = __salt__['pki.write_file_content'](newkey, keyfile)
|
wkey = __salt__['pki.write_file_content'](newkey, keyfile)
|
||||||
wfullcert = __salt__['pki.write_file_content'](newfullcert, fullcertfile)
|
wfullcert = __salt__['pki.write_file_content'](newfullcert, fullcertfile)
|
||||||
|
@ -5,6 +5,7 @@ acme:
|
|||||||
- "/etc/acme/dh/"
|
- "/etc/acme/dh/"
|
||||||
- "/etc/acme/keys/"
|
- "/etc/acme/keys/"
|
||||||
- "/etc/acme/certs/"
|
- "/etc/acme/certs/"
|
||||||
|
- "/etc/acme/fullchains/"
|
||||||
dh:
|
dh:
|
||||||
path: "/etc/acme/dh/dh.pem"
|
path: "/etc/acme/dh/dh.pem"
|
||||||
keysize: 2048
|
keysize: 2048
|
||||||
|
Loading…
Reference in New Issue
Block a user