Update to 2021-10-13 01:00

master
Daniel Berteaud 3 years ago
parent 415da1fcff
commit 07a0808fc5
  1. 8
      roles/letsencrypt/defaults/main.yml
  2. 4
      roles/letsencrypt/templates/config.j2

@ -16,6 +16,14 @@ letsencrypt_challenge: http
# letsencrypt_dns_provider: gandi # letsencrypt_dns_provider: gandi
# letsencrypt_dns_provider_options: '--api-protocol=rest' # letsencrypt_dns_provider_options: '--api-protocol=rest'
# letsencrypt_dns_auth_token: XXXX # letsencrypt_dns_auth_token: XXXX
# Specify a preferred chain of intermediate certs
# If not specified, it'll use the short ISRG Root X1 chain
# (not signed with the expired DST Root CA X3)
# The special value "default" means to omit the directive, and use the default
# dehydrated value
# letsencrypt_preferred_chain: default
# #
letsencrypt_certs: [] letsencrypt_certs: []
# letsencrypt_certs: # letsencrypt_certs:

@ -10,7 +10,11 @@ KEYSIZE="{{ letsencrypt_key_size | default('4096') }}"
HOOK=/usr/{{ (ansible_os_family == 'Debian') | ternary('local/','') }}bin/dehydrated_hooks HOOK=/usr/{{ (ansible_os_family == 'Debian') | ternary('local/','') }}bin/dehydrated_hooks
RENEW_DAYS="{{ letsencrypt_renew_days | default('30') }}" RENEW_DAYS="{{ letsencrypt_renew_days | default('30') }}"
PRIVATE_KEY_RENEW="yes" PRIVATE_KEY_RENEW="yes"
{% if letsencrypt_preferred_chain is not defined %}
PREFERRED_CHAIN="{{ letsencrypt_openssl_version.stdout is version('1.1', '>=') | ternary('ISRG Root X1','issuer= /C=US/O=Internet Security Research Group/CN=ISRG Root X1') }}" PREFERRED_CHAIN="{{ letsencrypt_openssl_version.stdout is version('1.1', '>=') | ternary('ISRG Root X1','issuer= /C=US/O=Internet Security Research Group/CN=ISRG Root X1') }}"
{% elif letsencrypt_preferred_chain != 'default' %}
PREFERRED_CHAIN={{ letsencrypt_preferred_chain | quote }}
{% endif %}
{% if letsencrypt_key_algo | default('rsa') in ['rsa', 'prime256v1', 'secp384r1' ] %} {% if letsencrypt_key_algo | default('rsa') in ['rsa', 'prime256v1', 'secp384r1' ] %}
KEY_ALGO={{ letsencrypt_key_algo | default('rsa') }} KEY_ALGO={{ letsencrypt_key_algo | default('rsa') }}
{% endif %} {% endif %}

Loading…
Cancel
Save