X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/21958591555b0b80370e944e3128ac5d533c281d..4687a5bf9faa00f2ff3a14545cdd58a65a65ab8d:/cookbooks/ssl/recipes/default.rb?ds=inline diff --git a/cookbooks/ssl/recipes/default.rb b/cookbooks/ssl/recipes/default.rb index c2e62d228..33c9bcb14 100644 --- a/cookbooks/ssl/recipes/default.rb +++ b/cookbooks/ssl/recipes/default.rb @@ -22,26 +22,28 @@ keys = data_bag_item("ssl", "keys") package "openssl" package "ssl-cert" -cookbook_file "/etc/ssl/certs/rapidssl.pem" do - owner "root" - group "root" - mode 0444 - backup false +%w(rapidssl startcom dhparam).each do |certificate| + cookbook_file "/etc/ssl/certs/#{certificate}.pem" do + owner "root" + group "root" + mode 0o444 + backup false + end end -["openstreetmap", "tile.openstreetmap", "crm.osmfoundation"].each do |certificate| +["openstreetmap", "tile.openstreetmap", "osmfoundation"].each do |certificate| if node[:ssl][:certificates].include?(certificate) cookbook_file "/etc/ssl/certs/#{certificate}.pem" do owner "root" group "root" - mode 0444 + mode 0o444 backup false end file "/etc/ssl/private/#{certificate}.key" do owner "root" group "ssl-cert" - mode 0440 + mode 0o440 content keys[certificate].join("\n") backup false end