X-Git-Url: https://gerrit.akraino.org/r/gitweb?a=blobdiff_plain;f=ocd%2Finfra%2Fplaybooks%2Froles%2Fmepserver%2Ftasks%2Finstall-ssl.yml;h=c4c941965157287c803b43e153a53345ae7f9340;hb=092b388768cca3f51e4191a183842287e5947fd0;hp=5aa5b436c4806ac63ef05ab75bf02c270d309aaf;hpb=42ca3fcbed3996d68e1e7d3035e5e859eef7edb5;p=ealt-edge.git diff --git a/ocd/infra/playbooks/roles/mepserver/tasks/install-ssl.yml b/ocd/infra/playbooks/roles/mepserver/tasks/install-ssl.yml index 5aa5b43..c4c9419 100644 --- a/ocd/infra/playbooks/roles/mepserver/tasks/install-ssl.yml +++ b/ocd/infra/playbooks/roles/mepserver/tasks/install-ssl.yml @@ -30,7 +30,7 @@ - name: modifying configuration to support https shell: - cmd: cp mep-k8s.yaml kong-k8s-ssl.yaml + cmd: cp kong-k8s.yaml kong-k8s-ssl.yaml chdir: /tmp/mepserver/deploy/ - name: modify configuraiton to support https @@ -43,6 +43,37 @@ cmd: chmod +x kongScript.sh && ./kongScript.sh chdir: /tmp/mepserver/deploy/ +- name: Generate Certificates + shell: +# yamllint disable rule:line-length + cmd: openssl genrsa -out ca.key 2048 + chdir: /tmp/mepserver/deploy/ + +- name: Generate Certificate - Step 2 + shell: + cmd: openssl req -new -key ca.key -subj /C=CN/ST=Peking/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out ca.csr + chdir: /tmp/mepserver/deploy/ + +- name: Generate Root Certificate + shell: + cmd: openssl x509 -req -days 365 -in ca.csr -extensions v3_req -signkey ca.key -out trust.cer + chdir: /tmp/mepserver/deploy/ + +- name: Generate TLS certificate and TLS Key + shell: + cmd: openssl genrsa -out server_key.pem 2048 + chdir: /tmp/mepserver/deploy/ + +- name: Generate TLS Certificate and TLS Key + shell: + cmd: openssl req -new -key server_key.pem -subj /C=CN/ST=Beijing/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out tls.csr + chdir: /tmp/mepserver/deploy/ + +- name: Generate TLS Certificate and TLS Key + shell: + cmd: openssl x509 -req -in tls.csr -extensions v3_req -CA trust.cer -CAkey ca.key -CAcreateserial -out server.cer + chdir: /tmp/mepserver/deploy/ + - name: Create mepssl-secret shell: # yamllint disable rule:line-length