From 3fa9d0cd553ba1b23dbaff2d9394e4b6758b7981 Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Thu, 11 Oct 2018 09:02:20 -0400 Subject: [PATCH] CA Module - Trying to fix SSL keys --- salt/ca/files/signing_policies.conf | 2 +- salt/common/init.sls | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/salt/ca/files/signing_policies.conf b/salt/ca/files/signing_policies.conf index 5d82b06f4..e29091a46 100644 --- a/salt/ca/files/signing_policies.conf +++ b/salt/ca/files/signing_policies.conf @@ -25,7 +25,7 @@ x509_signing_policies: - authorityKeyIdentifier: keyid,issuer:always - days_valid: 3000 - copypath: /etc/pki/issued_certs/ - master: + masterssl: - minions: '*' - signing_private_key: /etc/pki/ca.key - signing_cert: /etc/pki/ca.crt diff --git a/salt/common/init.sls b/salt/common/init.sls index 577cdb1f5..b7fbc2fb2 100644 --- a/salt/common/init.sls +++ b/salt/common/init.sls @@ -121,8 +121,8 @@ so-core: - /opt/so/log/nginx/:/var/log/nginx:rw - /opt/so/tmp/nginx/:/var/lib/nginx:rw - /opt/so/tmp/nginx/:/run:rw - - /etc/pki/master.crt:/etc/pki/nginx/server.crt:ro - - /etc/pki/master.key:/etc/pki/nginx/server.key:ro + - /etc/pki/masterssl.crt:/etc/pki/nginx/server.crt:ro + - /etc/pki/masterssl.key:/etc/pki/nginx/server.key:ro - cap_add: NET_BIND_SERVICE - port_bindings: