File tree Expand file tree Collapse file tree 2 files changed +19
-6
lines changed
templates/puppet/puppetdb Expand file tree Collapse file tree 2 files changed +19
-6
lines changed Original file line number Diff line number Diff line change 25
25
default => ' /var/lib/puppetdb' ,
26
26
}
27
27
28
+ $ssl_cert_path = debian::codename() ? {
29
+ ' bullseye' => ' /etc/puppetlabs/puppetdb/ssl/public.pem' ,
30
+ default => " /var/lib/puppet/ssl/certs/${facts['networking']['fqdn']}.pem" ,
31
+ }
32
+ $ssl_key_path = debian::codename() ? {
33
+ ' bullseye' => ' /etc/puppetlabs/puppetdb/ssl/private.pem' ,
34
+ default => " /var/lib/puppet/ssl/private_keys/${facts['networking']['fqdn']}.pem" ,
35
+ }
36
+ $ssl_ca_path = debian::codename() ? {
37
+ ' bullseye' => ' /etc/puppetlabs/puppetdb/ssl/ca.pem' ,
38
+ default => ' /etc/puppet/puppetserver/ca/ca_crt.pem' ,
39
+ }
40
+
28
41
file { "${config_path}/cert-allowlist" :
29
42
ensure => file ,
30
43
mode => ' 0444' ,
Original file line number Diff line number Diff line change @@ -15,9 +15,9 @@ server {
15
15
proxy_redirect off;
16
16
proxy_buffering off;
17
17
18
- proxy_ssl_certificate /etc/puppetlabs/puppetdb/ssl/public.pem ;
19
- proxy_ssl_certificate_key /etc/puppetlabs/puppetdb/ssl/private.pem ;
20
- proxy_ssl_trusted_certificate /etc/puppetlabs/puppetdb/ssl/ca.pem ;
18
+ proxy_ssl_certificate <%= @ssl_cert_path %> ;
19
+ proxy_ssl_certificate_key <%= @ssl_key_path %> ;
20
+ proxy_ssl_trusted_certificate <%= @ssl_ca_path %> ;
21
21
proxy_ssl_verify on;
22
22
proxy_ssl_protocols TLSv1.3;
23
23
}
@@ -27,9 +27,9 @@ server {
27
27
proxy_redirect off;
28
28
proxy_buffering off;
29
29
30
- proxy_ssl_certificate /etc/puppetlabs/puppetdb/ssl/public.pem ;
31
- proxy_ssl_certificate_key /etc/puppetlabs/puppetdb/ssl/private.pem ;
32
- proxy_ssl_trusted_certificate /etc/puppetlabs/puppetdb/ssl/ca.pem ;
30
+ proxy_ssl_certificate <%= @ssl_cert_path %> ;
31
+ proxy_ssl_certificate_key <%= @ssl_key_path %> ;
32
+ proxy_ssl_trusted_certificate <%= @ssl_ca_path %> ;
33
33
proxy_ssl_verify on;
34
34
proxy_ssl_protocols TLSv1.3;
35
35
}
You can’t perform that action at this time.
0 commit comments