From e7173e1d628230fb2895b5b2a88dfba3a7bd4cdb Mon Sep 17 00:00:00 2001 From: abelgana <32614067+abelgana@users.noreply.github.com> Date: Sat, 25 Nov 2017 17:29:21 -0500 Subject: [PATCH 1/2] Change altnames to alt_names Hi, Could you please check if it was a typo? https://www.vaultproject.io/api/secret/pki/ Regards, --- roles/vault/defaults/main.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/roles/vault/defaults/main.yml b/roles/vault/defaults/main.yml index f70d67f7d..540b91295 100644 --- a/roles/vault/defaults/main.yml +++ b/roles/vault/defaults/main.yml @@ -83,7 +83,7 @@ vault_ca_options: format: pem ttl: "{{ vault_max_lease_ttl }}" exclude_cn_from_sans: true - altnames: + alt_names: - "vault.{{ system_namespace }}.svc.{{ dns_domain }}" - "vault.{{ system_namespace }}.svc" - "vault.{{ system_namespace }}" From fe3290601a2edc47236faaae447fb8f70dfbba59 Mon Sep 17 00:00:00 2001 From: abelgana <32614067+abelgana@users.noreply.github.com> Date: Mon, 27 Nov 2017 06:57:16 -0500 Subject: [PATCH 2/2] The variable altnames is used by this task. Since the value will change on the default. It needs to change here also. --- roles/vault/tasks/bootstrap/gen_vault_certs.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/roles/vault/tasks/bootstrap/gen_vault_certs.yml b/roles/vault/tasks/bootstrap/gen_vault_certs.yml index 8a82e5b6f..d542ef845 100644 --- a/roles/vault/tasks/bootstrap/gen_vault_certs.yml +++ b/roles/vault/tasks/bootstrap/gen_vault_certs.yml @@ -2,7 +2,7 @@ - include: ../shared/issue_cert.yml vars: issue_cert_common_name: "{{ vault_pki_mounts.vault.roles[0].name }}" - issue_cert_alt_names: "{{ groups.vault + ['localhost'] + vault_ca_options.vault.altnames|default() }}" + issue_cert_alt_names: "{{ groups.vault + ['localhost'] + vault_ca_options.vault.alt_names|default() }}" issue_cert_hosts: "{{ groups.vault }}" issue_cert_ip_sans: >- [