X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/f601fd4a5494b22aba8edc3085a338feb67a9a2e..24bda5b91ff2677a586d2c8c16e0e44eafaa37bc:/cookbooks/ssl/recipes/default.rb?ds=sidebyside diff --git a/cookbooks/ssl/recipes/default.rb b/cookbooks/ssl/recipes/default.rb index 81dea8b28..328ba8bab 100644 --- a/cookbooks/ssl/recipes/default.rb +++ b/cookbooks/ssl/recipes/default.rb @@ -17,41 +17,14 @@ # limitations under the License. # -keys = data_bag_item("ssl", "keys") - package "openssl" package "ssl-cert" -cookbook_file "/etc/ssl/certs/rapidssl.pem" do - owner "root" - group "root" - mode 0444 - backup false -end - -[ "openstreetmap", "tile.openstreetmap" ].each do |certificate| - if node[:ssl][:certificates].include?(certificate) - cookbook_file "/etc/ssl/certs/#{certificate}.pem" do - owner "root" - group "root" - mode 0444 - backup false - end - - file "/etc/ssl/private/#{certificate}.key" do - owner "root" - group "ssl-cert" - mode 0440 - content keys[certificate].join("\n") - backup false - end - else - file "/etc/ssl/certs/#{certificate}.pem" do - action :delete - end - - file "/etc/ssl/private/#{certificate}.key" do - action :delete - end +%w(letsencrypt dhparam).each do |certificate| + cookbook_file "/etc/ssl/certs/#{certificate}.pem" do + owner "root" + group "root" + mode 0o444 + backup false end end