Skip to content

Commit 3b97e63

Browse files
committed
Story #15211: separate client and server certificate
1 parent 4f13fad commit 3b97e63

File tree

34 files changed

+383
-221
lines changed

34 files changed

+383
-221
lines changed

deployment/ansible-vitamui/app_api_gateway.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77
vars:
88
vitamui_struct: "{{ vitamui.api_gateway }}"
99
vitamui_certificate_type: external
10-
password_keystore: "{{ keystores_server_api_gateway }}"
10+
password_keystore_server: "{{ keystores_server_vitamui_services_api_gateway }}"
11+
password_keystore_client: "{{ keystores_client_vitamui_services_api_gateway }}"
1112
password_truststore: "{{ truststores_client_external }}"
1213
vitam_cert: "{{ vitam_certs.vitamui }}"

deployment/ansible-vitamui/app_archive_search.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77
vars:
88
vitamui_struct: "{{ vitamui.archive_search }}"
99
vitamui_certificate_type: external
10-
password_keystore: "{{ keystores_server_archive_search }}"
10+
password_keystore_server: "{{ keystores_server_vitamui_services_archive_search }}"
11+
password_keystore_client: "{{ keystores_client_vitamui_services_archive_search }}"
1112
password_truststore: "{{ truststores_client_external }}"
1213
vitam_cert: "{{ vitam_certs.vitamui }}"

deployment/ansible-vitamui/app_collect.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77
vars:
88
vitamui_struct: "{{ vitamui.collect }}"
99
vitamui_certificate_type: external
10-
password_keystore: "{{ keystores_server_collect }}"
10+
password_keystore_server: "{{ keystores_server_vitamui_services_collect }}"
11+
password_keystore_client: "{{ keystores_client_vitamui_services_collect }}"
1112
password_truststore: "{{ truststores_client_external }}"
1213
vitam_cert: "{{ vitam_certs.vitamui }}"

deployment/ansible-vitamui/app_ingest.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77
vars:
88
vitamui_struct: "{{ vitamui.ingest }}"
99
vitamui_certificate_type: external
10-
password_keystore: "{{ keystores_server_ingest }}"
10+
password_keystore_server: "{{ keystores_server_vitamui_services_ingest }}"
11+
password_keystore_client: "{{ keystores_client_vitamui_services_ingest }}"
1112
password_truststore: "{{ truststores_client_external }}"
1213
vitam_cert: "{{ vitam_certs.vitamui }}"

deployment/ansible-vitamui/app_pastis.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77
vars:
88
vitamui_struct: "{{ vitamui.pastis }}"
99
vitamui_certificate_type: external
10-
password_keystore: "{{ keystores_server_pastis }}"
10+
password_keystore_server: "{{ keystores_server_vitamui_services_pastis }}"
11+
password_keystore_client: "{{ keystores_client_vitamui_services_pastis }}"
1112
password_truststore: "{{ truststores_client_external }}"
1213
vitam_cert: "{{ vitam_certs.vitamui }}"

deployment/ansible-vitamui/app_referential.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77
vars:
88
vitamui_struct: "{{ vitamui.referential }}"
99
vitamui_certificate_type: external
10-
password_keystore: "{{ keystores_server_referential }}"
10+
password_keystore_server: "{{ keystores_server_vitamui_services_referential }}"
11+
password_keystore_client: "{{ keystores_client_vitamui_services_referential }}"
1112
password_truststore: "{{ truststores_client_external }}"
1213
vitam_cert: "{{ vitam_certs.vitamui }}"

deployment/ansible-vitamui/vitamui_apps.yml

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,8 +9,8 @@
99
vars:
1010
vitamui_struct: "{{ vitamui.security }}"
1111
vitamui_certificate_type: server
12-
password_keystore: "{{ keystores_server_security }}"
13-
password_truststore: "{{ truststores_server }}"
12+
password_keystore_server: "{{ keystores_server_vitamui_services_security }}"
13+
password_truststore: "{{ truststores_vitamui }}"
1414
tags: security
1515

1616
# External apps
@@ -22,7 +22,8 @@
2222
vars:
2323
vitamui_struct: "{{ vitamui.iam }}"
2424
vitamui_certificate_type: external
25-
password_keystore: "{{ keystores_server_iam }}"
25+
password_keystore_server: "{{ keystores_server_vitamui_services_iam }}"
26+
password_keystore_client: "{{ keystores_client_vitamui_services_iam }}"
2627
password_truststore: "{{ truststores_client_external }}"
2728
vitam_cert: "{{ vitam_certs.vitamui }}"
2829
tags: iam
@@ -36,6 +37,7 @@
3637
vars:
3738
vitamui_struct: "{{ vitamui.cas_server }}"
3839
vitamui_certificate_type: external
39-
password_keystore: "{{ keystores_server_cas_server }}"
40+
password_keystore_server: "{{ keystores_server_vitamui_services_cas_server }}"
41+
password_keystore_client: "{{ keystores_client_vitamui_services_cas_server }}"
4042
password_truststore: "{{ truststores_client_external }}"
4143
tags: cas-server

deployment/pki/config/crt-config

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -54,8 +54,8 @@ issuerAltName = issuer:copy
5454
subjectAltName = ${ENV::OPENSSL_SAN}
5555
basicConstraints = critical,CA:FALSE
5656
keyUsage = digitalSignature, keyEncipherment
57-
nsCertType = server, client
58-
extendedKeyUsage = serverAuth, clientAuth
57+
nsCertType = server
58+
extendedKeyUsage = serverAuth
5959

6060
[ extension_client ]
6161
nsComment = "Certificat Client SSL"

deployment/pki/scripts/generate_ca.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ set -e
1212
######################################################################
1313

1414
function get_autorities() {
15-
echo "server client-external client-vitam"
15+
echo "vitamui-services client-external client-vitam"
1616
}
1717

1818
######################################################################

deployment/pki/scripts/generate_ca_dev.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ set -e
1414
REPERTOIRE_ROOT="$( cd "$( readlink -f $(dirname ${BASH_SOURCE[0]}) )/../../../dev-deployment" ; pwd )"
1515

1616
function get_autorities() {
17-
echo "server client-external client-vitam"
17+
echo "vitamui-services client-external client-vitam"
1818
}
1919

2020
######################################################################

0 commit comments

Comments
 (0)