diff options
author | Jenkins <jenkins@review.openstack.org> | 2017-04-12 10:14:09 +0000 |
---|---|---|
committer | Gerrit Code Review <review@openstack.org> | 2017-04-12 10:14:09 +0000 |
commit | cb2393f6e003cea01231e50b93a19498fd2067c5 (patch) | |
tree | a528f7d04974baa22cff1e0c4ff02c12acdd3ebf /manifests/certmonger/apache_dirs.pp | |
parent | b10fa039b3db88908f3e9501d60750de9ffea073 (diff) | |
parent | bbe603a2608c43d9b68f998204e75b55621a9e8f (diff) |
Merge "Ensure directory exists for certificates for httpd"
Diffstat (limited to 'manifests/certmonger/apache_dirs.pp')
-rw-r--r-- | manifests/certmonger/apache_dirs.pp | 55 |
1 files changed, 55 insertions, 0 deletions
diff --git a/manifests/certmonger/apache_dirs.pp b/manifests/certmonger/apache_dirs.pp new file mode 100644 index 0000000..2588e46 --- /dev/null +++ b/manifests/certmonger/apache_dirs.pp @@ -0,0 +1,55 @@ +# Copyright 2017 Red Hat, Inc. +# +# Licensed under the Apache License, Version 2.0 (the "License"); you may +# not use this file except in compliance with the License. You may obtain +# a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT +# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the +# License for the specific language governing permissions and limitations +# under the License. +# +# : = Class: tripleo::certmonger::apache_dirs +# +# Creates the necessary directories for apache's certificates and keys in the +# assigned locations if specified. It also assigns the correct SELinux tags. +# +# === Parameters: +# +# [*certificate_dir*] +# (Optional) Directory where apache's certificates will be stored. If left +# unspecified, it won't be created. +# Defaults to undef +# +# [*key_dir*] +# (Optional) Directory where apache's keys will be stored. +# Defaults to undef +# +class tripleo::certmonger::apache_dirs( + $certificate_dir = undef, + $key_dir = undef, +){ + + if $certificate_dir { + file { $certificate_dir : + ensure => 'directory', + selrole => 'object_r', + seltype => 'cert_t', + seluser => 'system_u', + } + File[$certificate_dir] ~> Certmonger_certificate<| tag == 'apache-cert' |> + } + + if $key_dir { + file { $key_dir : + ensure => 'directory', + selrole => 'object_r', + seltype => 'cert_t', + seluser => 'system_u', + } + File[$key_dir] ~> Certmonger_certificate<| tag == 'apache-cert' |> + } +} |