New in version 2.7.
account_key_src, account_key_content, private_key_src or private_key_content must be specified.The below requirements are needed on the host that executes this module.
| Parameter | Choices/Defaults | Comments |
|---|---|---|
|
account_key_content
(added in 2.5) |
Content of the ACME account RSA or Elliptic Curve key.
Mutually exclusive with
account_key_src.Required if
account_key_src is not used.Warning: the content will be written into a temporary file, which will be deleted by Ansible when the module completes. Since this is an important private key — it can be used to change the account key, or to revoke your certificates without knowing their private keys —, this might not be acceptable.
|
|
| account_key_src |
Path to a file containing the ACME account RSA or Elliptic Curve key.
RSA keys can be created with
openssl rsa .... Elliptic curve keys can be created with openssl ecparam -genkey ....Mutually exclusive with
account_key_content.Required if
account_key_content is not used.aliases: account_key |
|
| acme_directory |
Default: https://acme-staging.api.letsencrypt.org/directory
|
The ACME directory to use. This is the entry point URL to access CA server API.
For safety reasons the default is set to the Let's Encrypt staging server (for the ACME v1 protocol). This will create technically correct, but untrusted certificates.
For Let's Encrypt, all staging endpoints can be found here: https://letsencrypt.org/docs/staging-environment/
For Let's Encrypt, the production directory URL for ACME v1 is https://acme-v01.api.letsencrypt.org/directory, and the production directory URL for ACME v2 is https://acme-v02.api.letsencrypt.org/directory.
Warning: So far, the module has only been tested against Let's Encrypt (staging and production) and against the Pebble testing server (https://github.com/letsencrypt/Pebble).
|
|
acme_version
(added in 2.5) |
|
The ACME version of the endpoint.
Must be 1 for the classic Let's Encrypt ACME endpoint, or 2 for the new standardized ACME v2 endpoint.
|
|
certificate
required |
Path to the certificate to revoke.
|
|
| private_key_content |
Content of the certificate's private key.
Note that exactly one of
account_key_src, account_key_content, private_key_src or private_key_content must be specified.Warning: the content will be written into a temporary file, which will be deleted by Ansible when the module completes. Since this is an important private key — it can be used to change the account key, or to revoke your certificates without knowing their private keys —, this might not be acceptable.
|
|
| private_key_src |
Path to the certificate's private key.
Note that exactly one of
account_key_src, account_key_content, private_key_src or private_key_content must be specified. |
|
| revoke_reason |
One of the revocation reasonCodes defined in https://tools.ietf.org/html/rfc5280#section-5.3.1.
Possible values are
0 (unspecified), 1 (keyCompromise), 2 (cACompromise), 3 (affiliationChanged), 4 (superseded), 5 (cessationOfOperation), 6 (certificateHold), 8 (removeFromCRL), 9 (privilegeWithdrawn), 10 (aACompromise) |
|
|
validate_certs
bool (added in 2.5) |
|
Whether calls to the ACME directory will validate TLS certificates.
Warning: Should only ever be set to
no for testing purposes, for example when testing against a local Pebble server. |
- name: Revoke certificate with account key
acme_certificate_revoke:
account_key_src: /etc/pki/cert/private/account.key
certificate: /etc/httpd/ssl/sample.com.crt
- name: Revoke certificate with certificate's private key
acme_certificate_revoke:
private_key_src: /etc/httpd/ssl/sample.com.key
certificate: /etc/httpd/ssl/sample.com.crt
This module is flagged as preview which means that it is not guaranteed to have a backwards compatible interface.
Hint
If you notice any issues in this documentation you can edit this document to improve it.