From 38c39642550f436ba97c99f6175c3f527785bd1c Mon Sep 17 00:00:00 2001 From: Andrew Bonney Date: Mon, 10 Jan 2022 10:52:15 +0000 Subject: [PATCH] Remove SSL variables which appear to be unused Whilst enabling TLS v1.3 in other roles these variables were noted which don't appear to be used anywhere in the role. Change-Id: I6b06486328ec0af05a17272be99a14911be9f4f7 --- defaults/main.yml | 16 ---------------- 1 file changed, 16 deletions(-) diff --git a/defaults/main.yml b/defaults/main.yml index 07714d1..11e2de7 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -211,22 +211,6 @@ barbican_wsgi_processes_max: 16 barbican_wsgi_processes: "{{ [[(ansible_facts['processor_vcpus']//ansible_facts['processor_threads_per_core'])|default(1), 1] | max *2, barbican_wsgi_processes_max] | min }}" barbican_wsgi_threads: 1 -barbican_ssl: false -barbican_ssl_cert: /etc/ssl/certs/barbican.pem -barbican_ssl_key: /etc/ssl/private/barbican.key -barbican_ssl_ca_cert: /etc/ssl/certs/barbican-ca.pem -barbican_ssl_protocol: "{{ ssl_protocol | default('ALL -SSLv2 -SSLv3 -TLSv1.0 -TLSv1.1') }}" -barbican_ssl_cipher_suite: "{{ ssl_cipher_suite | default('ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS') }}" - -# if using a self-signed certificate, set this to true to regenerate it -barbican_ssl_self_signed_regen: false -barbican_ssl_self_signed_subject: "/C=US/ST=Texas/L=San Antonio/O=IT/CN={{ internal_lb_vip_address }}/subjectAltName=IP.1={{ external_lb_vip_address }}" - -# Set these in user_variables to deploy custom certificates -#barbican_user_ssl_cert: -#barbican_user_ssl_key: -#barbican_user_ssl_ca_cert: - # Memcached override barbican_memcached_servers: "{{ memcached_servers }}"