Merge "TLS everywhere: Configure CA for mongodb"
This commit is contained in:
commit
0406be8328
@ -47,6 +47,11 @@ parameters:
|
||||
EnableInternalTLS:
|
||||
type: boolean
|
||||
default: false
|
||||
InternalTLSCAFile:
|
||||
default: '/etc/ipa/ca.crt'
|
||||
type: string
|
||||
description: Specifies the default CA cert to use if TLS is used for
|
||||
services in the internal network.
|
||||
|
||||
conditions:
|
||||
|
||||
@ -98,6 +103,7 @@ outputs:
|
||||
generate_service_certificates: true
|
||||
mongodb::server::ssl: true
|
||||
mongodb::server::ssl_key: '/etc/pki/tls/certs/mongodb.pem'
|
||||
mongodb::server::ssl_ca: {get_param: InternalTLSCAFile}
|
||||
mongodb_certificate_specs:
|
||||
service_pem: '/etc/pki/tls/certs/mongodb.pem'
|
||||
service_certificate: '/etc/pki/tls/certs/mongodb.crt'
|
||||
|
Loading…
x
Reference in New Issue
Block a user