Tweak elastic agent ssl gen

This commit is contained in:
Josh Brower
2022-09-14 08:10:42 -04:00
parent bf14612258
commit 6945596eee
2 changed files with 4 additions and 5 deletions

View File

@@ -57,7 +57,7 @@ x509_signing_policies:
- extendedKeyUsage: serverAuth - extendedKeyUsage: serverAuth
- days_valid: 820 - days_valid: 820
- copypath: /etc/pki/issued_certs/ - copypath: /etc/pki/issued_certs/
fleet: elasticfleet:
- minions: '*' - minions: '*'
- signing_private_key: /etc/pki/ca.key - signing_private_key: /etc/pki/ca.key
- signing_cert: /etc/pki/ca.crt - signing_cert: /etc/pki/ca.crt
@@ -65,9 +65,8 @@ x509_signing_policies:
- ST: Utah - ST: Utah
- L: Salt Lake City - L: Salt Lake City
- basicConstraints: "critical CA:false" - basicConstraints: "critical CA:false"
- keyUsage: "critical keyEncipherment" - keyUsage: "digitalSignature, nonRepudiation"
- subjectKeyIdentifier: hash - subjectKeyIdentifier: hash
- authorityKeyIdentifier: keyid,issuer:always - authorityKeyIdentifier: keyid,issuer:always
- extendedKeyUsage: serverAuth
- days_valid: 820 - days_valid: 820
- copypath: /etc/pki/issued_certs/ - copypath: /etc/pki/issued_certs/

View File

@@ -176,7 +176,7 @@ etc_elasticfleet_crt:
x509.certificate_managed: x509.certificate_managed:
- name: /etc/pki/elasticfleet.crt - name: /etc/pki/elasticfleet.crt
- ca_server: {{ ca_server }} - ca_server: {{ ca_server }}
- signing_policy: fleet - signing_policy: elasticfleet
- public_key: /etc/pki/elasticfleet.key - public_key: /etc/pki/elasticfleet.key
- CN: {{ GLOBALS.hostname }} - CN: {{ GLOBALS.hostname }}
- subjectAltName: DNS:{{ GLOBALS.hostname }}, IP:{{ GLOBALS.node_ip }} - subjectAltName: DNS:{{ GLOBALS.hostname }}, IP:{{ GLOBALS.node_ip }}
@@ -214,7 +214,7 @@ chownilogstashelasticfleetp8:
- group: 939 - group: 939
# Create Symlinks to the keys so I can distribute it to all the things # Create Symlinks to the keys so I can distribute it to all the things
elasticfleetdir: elasticfleetdircerts:
file.directory: file.directory:
- name: /opt/so/saltstack/local/salt/elastic-fleet/files/certs - name: /opt/so/saltstack/local/salt/elastic-fleet/files/certs
- makedirs: True - makedirs: True