X-Git-Url: https://git.openstreetmap.org/chef.git/blobdiff_plain/7b9ec4b60ee39614d1d083d7220e76b07d2b275f..b01508c721cd3253eabc4feeb18588bf1bdd2afa:/cookbooks/ssl/recipes/default.rb?ds=sidebyside diff --git a/cookbooks/ssl/recipes/default.rb b/cookbooks/ssl/recipes/default.rb index 4bbcea471..81dea8b28 100644 --- a/cookbooks/ssl/recipes/default.rb +++ b/cookbooks/ssl/recipes/default.rb @@ -29,17 +29,29 @@ cookbook_file "/etc/ssl/certs/rapidssl.pem" do backup false end -cookbook_file "/etc/ssl/certs/openstreetmap.pem" do - owner "root" - group "root" - mode 0444 - backup false -end +[ "openstreetmap", "tile.openstreetmap" ].each do |certificate| + if node[:ssl][:certificates].include?(certificate) + cookbook_file "/etc/ssl/certs/#{certificate}.pem" do + owner "root" + group "root" + mode 0444 + backup false + end -file "/etc/ssl/private/openstreetmap.key" do - owner "root" - group "ssl-cert" - mode 0440 - content keys["openstreetmap"].join("\n") - backup false + file "/etc/ssl/private/#{certificate}.key" do + owner "root" + group "ssl-cert" + mode 0440 + content keys[certificate].join("\n") + backup false + end + else + file "/etc/ssl/certs/#{certificate}.pem" do + action :delete + end + + file "/etc/ssl/private/#{certificate}.key" do + action :delete + end + end end