Nenhuma descrição

signing_policies.conf 1.3KB

1234567891011121314151617181920212223242526272829303132
  1. {% import 'globals.jinja' as globals -%}
  2. x509_signing_policies:
  3. deployment_client:
  4. - signing_private_key: /data/admin/pki/deployment/ca.key
  5. - signing_cert: /data/admin/pki/deployment/ca.crt
  6. - copypath: /data/admin/pki/deployment/issued_certs
  7. - prepend_cn: True
  8. - days_valid: 90
  9. - basicConstraints: "critical CA:false"
  10. - keyUsage: "critical keyEncipherment"
  11. - extendedKeyUsage: "clientAuth"
  12. - subjectKeyIdentifier: hash
  13. - authorityKeyIdentifier: keyid,issuer:always
  14. {%- for attr, value in pillar['global']['certificate_attributes']['deployment'].items() %}
  15. - {{ attr }}: {{ value }}
  16. {%- endfor %}
  17. deployment_server:
  18. - minions: {{ ','.join(globals.admin_hosts) }}
  19. - signing_private_key: /data/admin/pki/deployment/ca.key
  20. - signing_cert: /data/admin/pki/deployment/ca.crt
  21. - copypath: /data/admin/pki/deployment/issued_certs
  22. - prepend_cn: True
  23. - days_valid: 90
  24. - basicConstraints: "critical CA:false"
  25. - keyUsage: "critical keyEncipherment"
  26. - extendedKeyUsage: "serverAuth,clientAuth"
  27. - subjectKeyIdentifier: hash
  28. - authorityKeyIdentifier: keyid,issuer:always
  29. {%- for attr, value in pillar['global']['certificate_attributes']['deployment'].items() %}
  30. - {{ attr }}: {{ value }}
  31. {%- endfor %}