Commit 60b86311 authored by Administrator's avatar Administrator
Browse files

Merge branch 'root-master-patch-86503' into 'master'

Update run.yml

See merge request ansible/playbooks/idm-freeipa-setup-after!26
parents 821c4f1e 357cff11
Loading
Loading
Loading
Loading
+20 −18
Original line number Diff line number Diff line
@@ -27,38 +27,40 @@
  hosts: ipaserver:ipareplicas
  become: yes
  tasks:
    - name: Comment cert in httpd config
      ansible.builtin.lineinfile:
        path: "/etc/httpd/conf.d/ssl.conf"
        state: present
        insertafter: "^<VirtualHost +_default_:443>$"
        # insertbefore: "^</VirtualHost>$"
        regexp: "^SSLCertificateFile +/var/lib/ipa/certs/httpd.crt$"
        replace: "#SSLCertificateFile /var/lib/ipa/certs/httpd.crt"
    - name: Comment key in httpd config
      ansible.builtin.lineinfile:
        path: "/etc/httpd/conf.d/ssl.conf"
        state: present
        insertafter: "^<VirtualHost +_default_:443>$"
        # insertbefore: "^</VirtualHost>$"
        regexp: "^SSLCertificateKeyFile +/var/lib/ipa/private/httpd.key$"
        replace: "#SSLCertificateKeyFile /var/lib/ipa/private/httpd.key"
    # - name: Comment cert in httpd config
    #   ansible.builtin.lineinfile:
    #     path: "/etc/httpd/conf.d/ssl.conf"
    #     state: present
    #     insertafter: "^<VirtualHost +_default_:443>$"
    #     # insertbefore: "^</VirtualHost>$"
    #     regexp: "^SSLCertificateFile +/var/lib/ipa/certs/httpd.crt$"
    #     replace: "#SSLCertificateFile /var/lib/ipa/certs/httpd.crt"
    # - name: Comment key in httpd config
    #   ansible.builtin.lineinfile:
    #     path: "/etc/httpd/conf.d/ssl.conf"
    #     state: present
    #     insertafter: "^<VirtualHost +_default_:443>$"
    #     # insertbefore: "^</VirtualHost>$"
    #     regexp: "^SSLCertificateKeyFile +/var/lib/ipa/private/httpd.key$"
    #     replace: "#SSLCertificateKeyFile /var/lib/ipa/private/httpd.key"
    - name: Put cert in httpd config
      ansible.builtin.lineinfile:
        path: "/etc/httpd/conf.d/ssl.conf"
        state: present
        insertafter: "^<VirtualHost +_default_:443>$"
        # insertbefore: "^</VirtualHost>$"
        regexp: "^SSLCertificateFile +/var/lib/ipa/certs/httpd.crt$"
        regexp: "^SSLCertificateFile .*"
        replace: "SSLCertificateFile /opt/ssl/fullchain.pem"
        backup: yes
    - name: Put key in httpd config
      ansible.builtin.lineinfile:
        path: "/etc/httpd/conf.d/ssl.conf"
        state: present
        insertafter: "^<VirtualHost +_default_:443>$"
        # insertbefore: "^</VirtualHost>$"
        regexp: "^SSLCertificateKeyFile +/var/lib/ipa/private/httpd.key$"
        regexp: "^SSLCertificateKeyFile .*"
        replace: "SSLCertificateKeyFile /opt/ssl/privkey.pem"
        backup: yes

- name: Install ucarp with dependencies
  hosts: ipaserver:ipareplicas