Commit 03377087 authored by nanahira's avatar nanahira

move cert path

parent 0347771d
...@@ -6,6 +6,7 @@ ...@@ -6,6 +6,7 @@
with_items: with_items:
- config-per-user - config-per-user
- env-per-user - env-per-user
- certs
- name: ocserv.conf - name: ocserv.conf
template: template:
src: ./ocserv.conf.j2 src: ./ocserv.conf.j2
...@@ -22,7 +23,7 @@ ...@@ -22,7 +23,7 @@
- name: ocserv certs - name: ocserv certs
synchronize: synchronize:
src: ../certs/{{ocservCert}}/ src: ../certs/{{ocservCert}}/
dest: '{{ansible_user_dir}}/nextgen-network/services/ocserv/certs' dest: '{{ansible_user_dir}}/nextgen-network/services/ocserv/certs/{{ocservCert}}'
delete: yes delete: yes
copy_links: yes copy_links: yes
verify_host: no verify_host: no
......
...@@ -5,9 +5,9 @@ udp-port = {{ocservPort}} ...@@ -5,9 +5,9 @@ udp-port = {{ocservPort}}
run-as-user = nobody run-as-user = nobody
run-as-group = daemon run-as-group = daemon
socket-file = /run/ocserv.socket socket-file = /run/ocserv.socket
server-cert = /etc/ssl/certs/fullchain.pem server-cert = /etc/ssl/certs/{{ocervCert}}/fullchain.pem
server-key = /etc/ssl/certs/privkey.pem server-key = /etc/ssl/certs/{{ocervCert}}/privkey.pem
dh-params = /etc/ssl/certs/dhparam.pem dh-params = /etc/ssl/certs/{{ocervCert}}/dhparam.pem
isolate-workers = true isolate-workers = true
server-stats-reset-time = 604800 server-stats-reset-time = 604800
keepalive = 300 keepalive = 300
......
...@@ -291,7 +291,7 @@ class InventoryBuilder { ...@@ -291,7 +291,7 @@ class InventoryBuilder {
'./ocserv/config-per-user:/etc/ocserv/config-per-user:ro', './ocserv/config-per-user:/etc/ocserv/config-per-user:ro',
'./ocserv/env-per-user:/etc/ocserv/env-per-user:ro', './ocserv/env-per-user:/etc/ocserv/env-per-user:ro',
'./ocserv/ocpasswd:/etc/ocserv/ocpasswd:ro', './ocserv/ocpasswd:/etc/ocserv/ocpasswd:ro',
'./ocserv/certs:/etc/ssl/certs:ro', `./ocserv/certs/${local.ocservCert}:/etc/ssl/certs/${local.ocservCert}:ro`,
'$HOME/nextgen-network/scripts:$HOME/nextgen-network/scripts:ro' '$HOME/nextgen-network/scripts:$HOME/nextgen-network/scripts:ro'
] ]
}; };
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment