Skip to content

Commit 27a47ec

Browse files
committed
updating key sites
1 parent fadcf71 commit 27a47ec

File tree

4 files changed

+23
-11
lines changed

4 files changed

+23
-11
lines changed

defaults/main.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,10 @@ nginx_timeout: 180
3636
# App Protect Temporary Directory to use (Default: /tmp)
3737
app_protect_tempdir: /tmp
3838

39+
# Choose where to fetch the NGINX signing key from.
40+
# Default is the official NGINX signing key host.
41+
# nginx_signing_key: https://cs.nginx.com/static/keys/nginx_signing.key
42+
3943
# Choose where to fetch the NGINX App Protect signing key from.
4044
# Default is the official NGINX App Protect signing key host.
4145
# app_protect_signing_key: https://cs.nginx.com/static/keys/app-protect.key

tasks/keys/apt-key.yml

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,18 @@
11
---
2-
- name: "(Install: APT OSs) Set Default APT NGINX App Protect Signing Key URL"
2+
- name: "(Install: APT OSs) Set APT NGINX Signing Key URL"
33
set_fact:
44
key_value: "" # appeasing the linter
5-
default_keysite: "http://nginx.org/keys/nginx_signing.key"
5+
nginx_keysite: "{{ nginx_signing_key | default('https://cs.nginx.com/static/keys/nginx_signing.key') }}"
66

77
- name: "(Install: APT OSs) Set APT NGINX App Protect Signing Key URL"
88
set_fact:
99
key_value: "" # appeasing the linter
10-
keysite: "{{ app_protect_signing_key | default(default_keysite) }}"
10+
app_protect_keysite: "{{ app_protect_signing_key | default('https://cs.nginx.com/static/keys/app-protect.key') }}"
11+
12+
- name: "(Install: APT OSs) Add APT NGINX Signing Key"
13+
apt_key:
14+
url: "{{ nginx_keysite }}"
1115

1216
- name: "(Install: APT OSs) Add APT NGINX App Protect Signing Key"
1317
apt_key:
14-
url: "{{ keysite }}"
18+
url: "{{ app_protect_keysite }}"

tasks/keys/rpm-key.yml

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,18 @@
11
---
2-
- name: "(Install: RPM OSs) Set Default RPM NGINX App Protect Signing Key"
2+
- name: "(Install: RPM OSs) Set Default RPM NGINX Signing Key"
33
set_fact:
44
key_value: "" # appeasing the linter
5-
default_keysite: "http://nginx.org/keys/nginx_signing.key"
5+
nginx_keysite: "{{ nginx_signing_key | default('https://cs.nginx.com/static/keys/nginx_signing.key') }}"
66

7-
- name: "(Install: RPM OSs) Set RPM NGINX App Protect Signing Key URL"
7+
- name: "(Install: RPM OSs) Set Default RPM NGINX App Protect Signing Key"
88
set_fact:
99
key_value: "" # appeasing the linter
10-
keysite: "{{ app_protect_signing_key | default(default_keysite) }}"
10+
app_protect_keysite: "{{ app_protect_signing_key | default('https://cs.nginx.com/static/keys/app-protect.key') }}"
11+
12+
- name: "(Install: RPM OSs) Add RPM NGINX Signing Key"
13+
rpm_key:
14+
key: "{{ nginx_keysite }}"
1115

1216
- name: "(Install: RPM OSs) Add RPM NGINX App Protect Signing Key"
1317
rpm_key:
14-
key: "{{ keysite }}"
18+
key: "{{ app_protect_keysite }}"

tasks/setup-redhat-repos.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@
3131
sslclientcert: "/etc/ssl/nginx/{{ nginx_license.certificate | basename }}"
3232
sslclientkey: "/etc/ssl/nginx/{{ nginx_license.key | basename }}"
3333
enabled: true
34-
gpgcheck: false
34+
gpgcheck: true
3535
gpgkey: https://cs.nginx.com/static/keys/app-protect.key
3636
state: "{{ nginx_license_status | default ('present') }}"
3737

@@ -44,7 +44,7 @@
4444
sslclientcert: "/etc/ssl/nginx/{{ nginx_license.certificate | basename }}"
4545
sslclientkey: "/etc/ssl/nginx/{{ nginx_license.key | basename }}"
4646
enabled: true
47-
gpgcheck: false
47+
gpgcheck: true
4848
gpgkey: https://cs.nginx.com/static/keys/app-protect.key
4949
state: "{{ nginx_license_status | default ('present') }}"
5050
when: ansible_distribution != "Amazon"

0 commit comments

Comments
 (0)