File tree Expand file tree Collapse file tree 4 files changed +10
-5
lines changed
Expand file tree Collapse file tree 4 files changed +10
-5
lines changed Original file line number Diff line number Diff line change @@ -30,6 +30,11 @@ openvpn_keydir: "{{ openvpn_etcdir }}/keys"
3030# README. Then you can simply point this variable to the pki folder of the
3131# easyrsa installation and all keys/certificates will be located fine.
3232# }}}
33+
34+ openvpn_ca_certs_file : ' {{ openvpn_keydir }}/ca.crt'
35+ openvpn_server_cert_file : ' {{ openvpn_keydir }}/issued/server.crt'
36+ openvpn_server_key_file : ' {{ openvpn_keydir }}/private/server.key'
37+
3338# Server configuration {{{
3439# Default settings (See OpenVPN documentation)
3540openvpn_host : " {{ inventory_hostname }}"
Original file line number Diff line number Diff line change 1414 {{ openvpn_keydir }}/issued/{{ item }}.crt
1515 {{ openvpn_keydir }}/private/{{ item }}.key
1616 {{ item }}.ovpn
17- {{ openvpn_keydir }}/ca.crt
17+ {{ openvpn_ca_certs_file }}
1818 {{ openvpn_tls_key if openvpn_tls_auth else '' }}
1919 loop : " {{ openvpn_clients }}"
2020 loop_control :
Original file line number Diff line number Diff line change 11---
22- name : Read CA file
3- command : cat "{{ openvpn_keydir }}/ca.crt "
3+ command : cat "{{ openvpn_ca_certs_file }}"
44 no_log : true
55 register : openvpn_read_ca_file_results
66 changed_when : false
Original file line number Diff line number Diff line change @@ -42,9 +42,9 @@ dev {{ openvpn_dev }}
4242#
4343# Any X509 key management system can be used. OpenVPN can also use a PKCS #12
4444# formatted key file (see "pkcs12" directive in man page).
45- ca {{ openvpn_keydir }}/ca.crt
46- cert {{ openvpn_keydir }}/issued/server.crt
47- key {{ openvpn_keydir }}/private/server.key # This file should be kept secret
45+ ca {{ openvpn_ca_certs_file }}
46+ cert {{ openvpn_server_cert_file }}
47+ key {{ openvpn_server_key_file }} # This file should be kept secret
4848
4949# Diffie hellman parameters. Generate your own with: openssl dhparam -out
5050# dh1024.pem 1024 Substitute 2048 for 1024 if you are using 2048 bit keys.
You can’t perform that action at this time.
0 commit comments