X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/7b9ec4b60ee39614d1d083d7220e76b07d2b275f..40d07ae504526c1ee30fecd18f9cf3b32f6fd39d:/cookbooks/ssl/recipes/default.rb diff --git a/cookbooks/ssl/recipes/default.rb b/cookbooks/ssl/recipes/default.rb index 4bbcea471..ccb3508be 100644 --- a/cookbooks/ssl/recipes/default.rb +++ b/cookbooks/ssl/recipes/default.rb @@ -8,7 +8,7 @@ # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # -# http://www.apache.org/licenses/LICENSE-2.0 +# https://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, @@ -17,29 +17,18 @@ # limitations under the License. # -keys = data_bag_item("ssl", "keys") - package "openssl" package "ssl-cert" -cookbook_file "/etc/ssl/certs/rapidssl.pem" do +cookbook_file "/etc/ssl/certs/letsencrypt.pem" do owner "root" group "root" - mode 0444 + mode 0o444 backup false end -cookbook_file "/etc/ssl/certs/openstreetmap.pem" do +openssl_dhparam "/etc/ssl/certs/dhparam.pem" do owner "root" group "root" - mode 0444 - backup false -end - -file "/etc/ssl/private/openstreetmap.key" do - owner "root" - group "ssl-cert" - mode 0440 - content keys["openstreetmap"].join("\n") - backup false + mode 0o444 end