From 766bba2fe538c929d4cad41c3c698d6aae6e881f Mon Sep 17 00:00:00 2001 From: Clark Boylan Date: Wed, 23 Aug 2017 16:52:55 -0700 Subject: [PATCH] Update infracloud-vanilla public ssl cert Our old self signed ssl cert has expired. Rather than need to maintain a CA for infracloud or sort out how we want to sign things lets just go ahead and use our snakeoil cert on the controller. The two big drawbacks to this approach are the long length of time this cert is valid for and it forces us to use a single controller host per cloud. Note that private hiera will have to be updated with the private key that corresponds to this (is the private portion of the snake oil cert on controller00.vanilla). Change-Id: I70de0416534f1b202c7c66c127777b7edc17486e --- hiera/common.yaml | 35 ++++++++++++++++------------------- 1 file changed, 16 insertions(+), 19 deletions(-) diff --git a/hiera/common.yaml b/hiera/common.yaml index c785a9f142..7a9d966c25 100644 --- a/hiera/common.yaml +++ b/hiera/common.yaml @@ -523,25 +523,22 @@ infracloud_hpuseast_ssl_cert_file_contents: | -----END CERTIFICATE----- infracloud_vanilla_ssl_cert_file_contents: | -----BEGIN CERTIFICATE----- - MIIDdjCCAl4CCQDQFWVmTcuNiDANBgkqhkiG9w0BAQsFADB9MQswCQYDVQQGEwJV - UzEOMAwGA1UECAwFVGV4YXMxDzANBgNVBAcMBkF1c3RpbjEdMBsGA1UECgwUT3Bl - blN0YWNrIEZvdW5kYXRpb24xLjAsBgNVBAMMJWNvbnRyb2xsZXIwMC52YW5pbGxh - LmljLm9wZW5zdGFjay5vcmcwHhcNMTYwODIzMTMyNjI4WhcNMTcwODIzMTMyNjI4 - WjB9MQswCQYDVQQGEwJVUzEOMAwGA1UECAwFVGV4YXMxDzANBgNVBAcMBkF1c3Rp - bjEdMBsGA1UECgwUT3BlblN0YWNrIEZvdW5kYXRpb24xLjAsBgNVBAMMJWNvbnRy - b2xsZXIwMC52YW5pbGxhLmljLm9wZW5zdGFjay5vcmcwggEiMA0GCSqGSIb3DQEB - AQUAA4IBDwAwggEKAoIBAQCtIrShw9VQnPiwr/AeS/gNoVkmoeXeXzWUY8UTJxes - MIBWvyhep60tFnoBZkda4aEDmEluSXaZH54yVlRhxLqT0bQjQaPcXcdQJvziHGqk - bFlL5SzRk7DmjIGQ7/j6AeGyAIXit8yjydLSmVd+b0152UTZ3bqsUyH5E+x2xm/b - d/xJChf63pO/StTlqeH6/bY1Ro4LUwdrJ/7jygFkGhqG9A0iJY12F4p6rwYIqmje - jMFqwK2aSkEF84/Ro/YwzfdPJ49sj6Kjtqg75RwV7gJKXDmiRIxs7bzh5zgZQcw/ - j4VTr+SUCnJsARckXu2eTEghdlSUaQPZx9NXwwkSHm7JAgMBAAEwDQYJKoZIhvcN - AQELBQADggEBAHPyQr3bEuHKHtCqZ2xc3LlnFJLgQ+ZaLxkVD0eoHULHpkV+2OK1 - OIFtWxvXRIG/+2xpuBfgyyyhb9AEgE7r0uIJSz+m4ZdjpmDw2+/dZt/cr4scPSOi - yV4qXZ5TZXhzD68bhsb5lFI0x8kjyMPX3DQqAVDpY+Jl6yu1LBxypp13mmVxy0no - kAzF7D2Plfhk3mgoUyacyGbDUXY80R3Q9XDu/mVarABmkztGUwTWZs8uHXf6v58M - hfdr6ZicTz+h4vtkoCqrm/QOX3eIN9N15GYAG1BxZP6x7T8QefX8/qWiYqI4evMk - 19radbtv323x4JZuH2DJ7Xx5597v303Ds0Y= + MIIC8DCCAdigAwIBAgIJAKnLfUr0fN5bMA0GCSqGSIb3DQEBCwUAMDAxLjAsBgNV + BAMTJWNvbnRyb2xsZXIwMC52YW5pbGxhLmljLm9wZW5zdGFjay5vcmcwHhcNMTYw + ODIzMDg0MTMzWhcNMjYwODIxMDg0MTMzWjAwMS4wLAYDVQQDEyVjb250cm9sbGVy + MDAudmFuaWxsYS5pYy5vcGVuc3RhY2sub3JnMIIBIjANBgkqhkiG9w0BAQEFAAOC + AQ8AMIIBCgKCAQEA14C9pRprywQM3USXg+doOJOXXSNZzHAEnZ12qQ5kWV150EY1 + XO92qZ5GJDomuVjxxW4WcH3FWbj0+fUHw6uWefeHhhTCI5PgeH95qlxPxzfsfLpy + Fx6JBaDTpfAaxlnlKtPsr6D1QwuAt53Q9imrPolrwuwelKgJMouDodfm9uDMbobU + jRd/vvXcOdw8HUxQE5pwwHyjUrYC0J4zclg+oVt7/WrfQUxXtsdBwDsoE08iBbrA + zSuU6ZNB+T/KJXgKcRozDQzwQW1K1C2i2062ZSw4khreqOhYe7CqRdFZMU5hh/Ih + LlNzIaHATJc6K0RaRZ7SMG9yE9OgnI4oWeYCzwIDAQABow0wCzAJBgNVHRMEAjAA + MA0GCSqGSIb3DQEBCwUAA4IBAQB/q7qC9Giv5XbeLng01M3Pnbxj/ixRt5/YYA+m + 6OuzxDYgZHaJf7+EIHspfL+Q7grGX/7wsbJPtqx0IYhMRfKcOWVF4x4i0bTyiX23 + 5lPl2aPhQjH4dhnkAB7KbLKyqTRoaTX7NOKbiHQ43R3AtuqMAFVc6M8R9pAPVq3n + +URMb2i9MYTmnobZCRR8Kdg3PFE06rYlYGSzWj6l7bzFXLVJPOvRoc2ONmofTJ4d + UnQw19SK7OyeYbWwUFT2yEXyG5NTe1ZxPTtEnCEXEuK19gDxnvOceUpRgJuWoyjL + b0KPvk0AyP+1Bb2f6UKo9539EvakMYTEqpuPlMDwyjq7olwr -----END CERTIFICATE----- infracloud_chocolate_ssl_cert_file_contents: | -----BEGIN CERTIFICATE-----