fixup! pki: add new vault root ca to pki
Some checks failed
Run nix flake check / flake-check (push) Failing after 13m24s
Some checks failed
Run nix flake check / flake-check (push) Failing after 13m24s
This commit is contained in:
@@ -99,10 +99,11 @@ let
|
|||||||
# ACME certificate directory
|
# ACME certificate directory
|
||||||
CERT_DIR="/var/lib/acme/vault01.home.2rjus.net"
|
CERT_DIR="/var/lib/acme/vault01.home.2rjus.net"
|
||||||
|
|
||||||
# Issue certificate for vault01
|
# Issue certificate for vault01 with vault as SAN
|
||||||
echo "Issuing certificate for vault01.home.2rjus.net..."
|
echo "Issuing certificate for vault01.home.2rjus.net (with SAN: vault.home.2rjus.net)..."
|
||||||
OUTPUT=$(bao write -format=json pki_int/issue/homelab \
|
OUTPUT=$(bao write -format=json pki_int/issue/homelab \
|
||||||
common_name="vault01.home.2rjus.net" \
|
common_name="vault01.home.2rjus.net" \
|
||||||
|
alt_names="vault.home.2rjus.net" \
|
||||||
ttl="720h")
|
ttl="720h")
|
||||||
|
|
||||||
# Create ACME directory structure
|
# Create ACME directory structure
|
||||||
@@ -140,6 +141,9 @@ let
|
|||||||
echo ""
|
echo ""
|
||||||
echo "Certificate details:"
|
echo "Certificate details:"
|
||||||
openssl x509 -in "$CERT_DIR/cert.pem" -noout -subject -issuer -dates
|
openssl x509 -in "$CERT_DIR/cert.pem" -noout -subject -issuer -dates
|
||||||
|
echo ""
|
||||||
|
echo "Subject Alternative Names:"
|
||||||
|
openssl x509 -in "$CERT_DIR/cert.pem" -noout -ext subjectAltName
|
||||||
|
|
||||||
echo ""
|
echo ""
|
||||||
echo "Now restart openbao service:"
|
echo "Now restart openbao service:"
|
||||||
@@ -195,6 +199,6 @@ in
|
|||||||
server = "https://vault01.home.2rjus.net:8200/v1/pki_int/acme/directory";
|
server = "https://vault01.home.2rjus.net:8200/v1/pki_int/acme/directory";
|
||||||
listenHTTP = ":80";
|
listenHTTP = ":80";
|
||||||
reloadServices = [ "openbao" ];
|
reloadServices = [ "openbao" ];
|
||||||
# extraDomainNames = [ "vault.home.2rjus.net" ];
|
extraDomainNames = [ "vault.home.2rjus.net" ];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user