|
18 | 18 | Stdlib::Absolutepath $foreman_ssl_key = '/etc/foreman-proxy/foreman_ssl_key.pem', |
19 | 19 | Stdlib::Absolutepath $foreman_ssl_ca_cert = '/etc/foreman-proxy/foreman_ssl_ca.pem', |
20 | 20 | Stdlib::Absolutepath $pki_dir = $certs::pki_dir, |
21 | | - Stdlib::Absolutepath $server_ca_cert = $certs::katello_server_ca_cert, |
22 | 21 | Optional[Stdlib::Absolutepath] $server_cert = $certs::server_cert, |
23 | 22 | Optional[Stdlib::Absolutepath] $server_key = $certs::server_key, |
24 | 23 | Optional[Stdlib::Absolutepath] $server_cert_req = $certs::server_cert_req, |
25 | 24 | String[2,2] $country = $certs::country, |
26 | 25 | String $state = $certs::state, |
27 | 26 | String $city = $certs::city, |
28 | 27 | String $expiration = $certs::expiration, |
29 | | - Stdlib::Absolutepath $default_ca_cert = $certs::katello_default_ca_cert, |
| 28 | + Stdlib::Absolutepath $default_ca_cert = $certs::ca::default_ca_path, |
30 | 29 | Stdlib::Absolutepath $ca_key_password_file = $certs::ca_key_password_file, |
31 | 30 | String $group = 'foreman-proxy', |
32 | 31 | String $owner = 'root', |
|
108 | 107 |
|
109 | 108 | if $deploy { |
110 | 109 | include certs::config::deploy |
| 110 | + require certs::ca |
111 | 111 |
|
112 | 112 | certs::keypair { $proxy_cert_name: |
113 | 113 | source_dir => "${certs::ssl_build_dir}/${hostname}", |
|
123 | 123 | } |
124 | 124 |
|
125 | 125 | file { $proxy_ca_cert: |
126 | | - ensure => file, |
127 | | - source => $default_ca_cert, |
128 | | - owner => $owner, |
129 | | - group => $group, |
130 | | - mode => '0440', |
131 | | - require => File[$default_ca_cert], |
| 126 | + ensure => file, |
| 127 | + source => $default_ca_cert, |
| 128 | + owner => $owner, |
| 129 | + group => $group, |
| 130 | + mode => '0440', |
132 | 131 | } |
133 | 132 |
|
134 | 133 | certs::keypair { $foreman_proxy_client_cert_name: |
|
145 | 144 | } |
146 | 145 |
|
147 | 146 | file { $foreman_ssl_ca_cert: |
148 | | - ensure => file, |
149 | | - source => $server_ca_cert, |
150 | | - owner => $owner, |
151 | | - group => $group, |
152 | | - mode => '0440', |
153 | | - require => File[$server_ca_cert], |
| 147 | + ensure => file, |
| 148 | + source => $certs::ca::server_ca_path, |
| 149 | + owner => $owner, |
| 150 | + group => $group, |
| 151 | + mode => '0440', |
154 | 152 | } |
155 | 153 |
|
156 | 154 | cert_key_bundle { $foreman_proxy_ssl_client_bundle: |
|
0 commit comments