X-Git-Url: https://git.openstreetmap.org/chef.git/blobdiff_plain/5919a0168e927c655ce23acc885413864f0ebfcf..45dde9418dd342bb1a632d82559201c0b3becf1a:/cookbooks/ssl/recipes/default.rb?ds=sidebyside diff --git a/cookbooks/ssl/recipes/default.rb b/cookbooks/ssl/recipes/default.rb index ee4b93327..674c8768d 100644 --- a/cookbooks/ssl/recipes/default.rb +++ b/cookbooks/ssl/recipes/default.rb @@ -1,14 +1,14 @@ # -# Cookbook Name:: ssl +# Cookbook:: ssl # Recipe:: default # -# Copyright 2011, OpenStreetMap Foundation +# Copyright:: 2011, OpenStreetMap Foundation # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # -# http://www.apache.org/licenses/LICENSE-2.0 +# https://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, @@ -17,41 +17,18 @@ # limitations under the License. # -keys = data_bag_item("ssl", "keys") - package "openssl" package "ssl-cert" -cookbook_file "/etc/ssl/certs/rapidssl.pem" do +cookbook_file "/etc/ssl/certs/letsencrypt.pem" do owner "root" group "root" - mode 0444 + mode 0o444 backup false end -[ "openstreetmap", "tile.openstreetmap", "crm.osmfoundation" ].each do |certificate| - if node[:ssl][:certificates].include?(certificate) - cookbook_file "/etc/ssl/certs/#{certificate}.pem" do - owner "root" - group "root" - mode 0444 - backup false - end - - file "/etc/ssl/private/#{certificate}.key" do - owner "root" - group "ssl-cert" - mode 0440 - content keys[certificate].join("\n") - backup false - end - else - file "/etc/ssl/certs/#{certificate}.pem" do - action :delete - end - - file "/etc/ssl/private/#{certificate}.key" do - action :delete - end - end +openssl_dhparam "/etc/ssl/certs/dhparam.pem" do + owner "root" + group "root" + mode 0o444 end