Page MenuHomeDevCentral

Enforce correct attributes for acme.sh private keys
ClosedPublic

Authored by dereckson on Fri, Oct 10, 22:19.
Tags
None
Referenced Files
F12346877: D3732.id9652.diff
Mon, Oct 27, 09:06
F12346876: D3732.id9730.diff
Mon, Oct 27, 09:06
F12345436: D3732.diff
Mon, Oct 27, 05:37
F12344862: D3732.id9730.diff
Mon, Oct 27, 03:49
F12344861: D3732.id9652.diff
Mon, Oct 27, 03:49
F12344170: D3732.id.diff
Mon, Oct 27, 02:56
F12342814: D3732.id9730.diff
Sun, Oct 26, 23:20
Unknown Object (File)
Sat, Oct 25, 13:43
Subscribers
None

Details

Summary

Apply logic from 421712d5da56 to private key files too, so several applications
can access the certificate private key they need.

Ref T2132

Test Plan

When run on Hervil, confirmed no-op as keys are already 640/600.

Diff Detail

Repository
rOPS Nasqueron Operations
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

dereckson created this revision.
Complector
$ salt hervil state.apply roles/core/certificates/acmesh test=True
[...]
----------                                                                                                
          ID: /var/certificates/mail.nasqueron.org/key.pem                                                
    Function: file.managed
      Result: True
     Comment: File /var/certificates/mail.nasqueron.org/key.pem not updated
     Started: 22:16:57.301699
    Duration: 1.387 ms
     Changes:   
----------
[...]
This revision is now accepted and ready to land.Mon, Oct 13, 17:08