|
@@ -28,7 +28,7 @@
|
28
|
28
|
dest=/etc/cron.monthly/letsencrypt-renew
|
29
|
29
|
owner=root
|
30
|
30
|
group=root
|
31
|
|
- mode=755
|
|
31
|
+ mode=0755
|
32
|
32
|
|
33
|
33
|
- name: Create live directory for LetsEncrypt cron job
|
34
|
34
|
file: state=directory path=/etc/letsencrypt/live group=root owner=root
|
|
@@ -38,26 +38,26 @@
|
38
|
38
|
when: ansible_ssh_user != "vagrant"
|
39
|
39
|
|
40
|
40
|
- name: Modify permissions to allow ssl-cert group access
|
41
|
|
- file: path=/etc/letsencrypt/archive owner=root group=ssl-cert mode=750
|
|
41
|
+ file: path=/etc/letsencrypt/archive owner=root group=ssl-cert mode=0750
|
42
|
42
|
when: ansible_ssh_user != "vagrant"
|
43
|
43
|
|
44
|
44
|
### Several steps to install a self-signed wildcard key to support offline testing
|
45
|
45
|
|
46
|
46
|
- name: Create live directory for testing keys
|
47
|
47
|
file: dest=/etc/letsencrypt/live/{{ domain }} state=directory
|
48
|
|
- owner=root group=root mode=755
|
|
48
|
+ owner=root group=root mode=0755
|
49
|
49
|
when: ansible_ssh_user == "vagrant"
|
50
|
50
|
|
51
|
51
|
- name: Copy SSL wildcard private key for testing
|
52
|
52
|
copy: src=wildcard_private.key
|
53
|
53
|
dest=/etc/letsencrypt/live/{{ domain }}/privkey.pem
|
54
|
|
- owner=root group=ssl-cert mode=640
|
|
54
|
+ owner=root group=ssl-cert mode=0640
|
55
|
55
|
when: ansible_ssh_user == "vagrant"
|
56
|
56
|
|
57
|
57
|
- name: Copy SSL public certificate into place for testing
|
58
|
58
|
copy: src=wildcard_public_cert.crt
|
59
|
59
|
dest=/etc/letsencrypt/live/{{ domain }}/cert.pem
|
60
|
|
- group=root owner=root mode=644
|
|
60
|
+ group=root owner=root mode=0644
|
61
|
61
|
register: certificate
|
62
|
62
|
notify: restart apache
|
63
|
63
|
when: ansible_ssh_user == "vagrant"
|
|
@@ -65,7 +65,7 @@
|
65
|
65
|
- name: Copy SSL CA combined certificate into place for testing
|
66
|
66
|
copy: src=wildcard_ca.pem
|
67
|
67
|
dest=/etc/letsencrypt/live/{{ domain }}/chain.pem
|
68
|
|
- group=root owner=root mode=644
|
|
68
|
+ group=root owner=root mode=0644
|
69
|
69
|
register: ca_certificate
|
70
|
70
|
notify: restart apache
|
71
|
71
|
when: ansible_ssh_user == "vagrant"
|
|
@@ -78,7 +78,7 @@
|
78
|
78
|
when: ansible_ssh_user == "vagrant"
|
79
|
79
|
|
80
|
80
|
- name: Set permissions on combined SSL public cert
|
81
|
|
- file: name=/etc/letsencrypt/live/{{ domain }}/fullchain.pem mode=644
|
|
81
|
+ file: name=/etc/letsencrypt/live/{{ domain }}/fullchain.pem mode=0644
|
82
|
82
|
notify: restart apache
|
83
|
83
|
when: ansible_ssh_user == "vagrant"
|
84
|
84
|
|