From b05e8debde9ae61ab1baadd4bf23f532b29a9a5f Mon Sep 17 00:00:00 2001 From: Juan Antonio Osorio Robles Date: Mon, 18 Jul 2016 18:00:14 +0300 Subject: Add principal to certmonger's haproxy helper The principal is needed for kerberos-based solutions like FreeIPA. bp tls-via-certmonger Change-Id: Ie27848f522d11135b061aef766de2b696c77fcb9 --- manifests/certmonger/haproxy.pp | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'manifests/certmonger') diff --git a/manifests/certmonger/haproxy.pp b/manifests/certmonger/haproxy.pp index 0806e40..2b738e6 100644 --- a/manifests/certmonger/haproxy.pp +++ b/manifests/certmonger/haproxy.pp @@ -36,18 +36,23 @@ # The post-save-command that certmonger will use once it renews the # certificate. # +# [*principal*] +# The haproxy service principal that is set for HAProxy in kerberos. +# define tripleo::certmonger::haproxy ( $service_pem, $service_certificate, $service_key, $hostname, $postsave_cmd, + $principal = undef, ){ certmonger_certificate { "${title}-cert": hostname => $hostname, certfile => $service_certificate, keyfile => $service_key, postsave_cmd => $postsave_cmd, + principal => $principal, } concat { $service_pem : ensure => present, -- cgit 1.2.3-korg