New DNS key
parent
80040dd35c
commit
4e6571a179
|
@ -40,6 +40,7 @@
|
||||||
- hosts: silice.adm.crans.org,sputnik.adm.crans.org,boeing.adm.crans.org
|
- hosts: silice.adm.crans.org,sputnik.adm.crans.org,boeing.adm.crans.org
|
||||||
vars:
|
vars:
|
||||||
certbot_dns_secret: "{{ vault_certbot_dns_secret }}"
|
certbot_dns_secret: "{{ vault_certbot_dns_secret }}"
|
||||||
|
certbot_adm_dns_secret: "{{ vault_certbot_adm_dns_secret }}"
|
||||||
bind:
|
bind:
|
||||||
masters: "{{ lookup('re2oapi', 'get_role', 'dns-authoritary-master')[0] }}"
|
masters: "{{ lookup('re2oapi', 'get_role', 'dns-authoritary-master')[0] }}"
|
||||||
slaves: "{{ lookup('re2oapi', 'get_role', 'dns-authoritary-slave')[0] }}"
|
slaves: "{{ lookup('re2oapi', 'get_role', 'dns-authoritary-slave')[0] }}"
|
||||||
|
|
|
@ -10,6 +10,10 @@ key "certbot_challenge." {
|
||||||
algorithm hmac-sha512;
|
algorithm hmac-sha512;
|
||||||
secret "{{ certbot_dns_secret }}";
|
secret "{{ certbot_dns_secret }}";
|
||||||
};
|
};
|
||||||
|
key "certbot_adm_challenge." {
|
||||||
|
algorithm hmac-sha512;
|
||||||
|
secret "{{ certbot_adm_dns_secret }}";
|
||||||
|
};
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
// Let's Encrypt Challenge DNS-01 zone
|
// Let's Encrypt Challenge DNS-01 zone
|
||||||
|
@ -41,7 +45,7 @@ zone "_acme-challenge.adm.crans.org" {
|
||||||
type master;
|
type master;
|
||||||
notify yes;
|
notify yes;
|
||||||
update-policy {
|
update-policy {
|
||||||
grant certbot_challenge. name _acme-challenge.adm.crans.org. txt;
|
grant certbot_adm_challenge. name _acme-challenge.adm.crans.org. txt;
|
||||||
};
|
};
|
||||||
{% else %}
|
{% else %}
|
||||||
type slave;
|
type slave;
|
||||||
|
|
|
@ -24,6 +24,6 @@
|
||||||
|
|
||||||
- name: Add Certbot configuration
|
- name: Add Certbot configuration
|
||||||
template:
|
template:
|
||||||
src: "letsencrypt/conf.d/{{ certbot.certname }}.ini.j2"
|
src: "letsencrypt/conf.d/certname.ini.j2"
|
||||||
dest: "/etc/letsencrypt/conf.d/{{ certbot.certname }}.ini"
|
dest: "/etc/letsencrypt/conf.d/{{ certbot.certname }}.ini"
|
||||||
mode: 0644
|
mode: 0644
|
||||||
|
|
Loading…
Reference in New Issue