Documentation

acme_certificate_revoke - Revoke certificates with the ACME protocol.

New in version 2.7.

Synopsis

  • Allows to revoke certificates with the ACME protocol. This protocol is, for example, used by Let’s Encrypt.
  • Note that exactly one of account_key_src, account_key_content, private_key_src or private_key_content must be specified.
  • Also note that in general, trying to revoke an already revoked certificate will lead to an error. The module tries to detect some common error messages (for example, the ones issued by Let’s Encrypt‘s Boulder software), but this might stop working and probably will not work for other server softwares.

Requirements

The below requirements are needed on the host that executes this module.

  • python >= 2.6
  • openssl

Parameters

Parameter Choices/Defaults Comments
account_key_content
(added in 2.5)
Content of the ACME account RSA or Elliptic Curve key.
Mutually exclusive with account_key_src.
Required if account_key_src is not used.
Warning: the content will be written into a temporary file, which will be deleted by Ansible when the module completes. Since this is an important private key — it can be used to change the account key, or to revoke your certificates without knowing their private keys —, this might not be acceptable.
account_key_src
Path to a file containing the ACME account RSA or Elliptic Curve key.
RSA keys can be created with openssl rsa .... Elliptic curve keys can be created with openssl ecparam -genkey ....
Mutually exclusive with account_key_content.
Required if account_key_content is not used.

aliases: account_key
acme_directory Default:
https://acme-staging.api.letsencrypt.org/directory
The ACME directory to use. This is the entry point URL to access CA server API.
For safety reasons the default is set to the Let's Encrypt staging server (for the ACME v1 protocol). This will create technically correct, but untrusted certificates.
For Let's Encrypt, all staging endpoints can be found here: https://letsencrypt.org/docs/staging-environment/
For Let's Encrypt, the production directory URL for ACME v1 is https://acme-v01.api.letsencrypt.org/directory, and the production directory URL for ACME v2 is https://acme-v02.api.letsencrypt.org/directory.
Warning: So far, the module has only been tested against Let's Encrypt (staging and production) and against the Pebble testing server (https://github.com/letsencrypt/Pebble).
acme_version
(added in 2.5)
    Choices:
  • 1 ←
  • 2
The ACME version of the endpoint.
Must be 1 for the classic Let's Encrypt ACME endpoint, or 2 for the new standardized ACME v2 endpoint.
certificate
required
Path to the certificate to revoke.
private_key_content
Content of the certificate's private key.
Note that exactly one of account_key_src, account_key_content, private_key_src or private_key_content must be specified.
Warning: the content will be written into a temporary file, which will be deleted by Ansible when the module completes. Since this is an important private key — it can be used to change the account key, or to revoke your certificates without knowing their private keys —, this might not be acceptable.
private_key_src
Path to the certificate's private key.
Note that exactly one of account_key_src, account_key_content, private_key_src or private_key_content must be specified.
revoke_reason
One of the revocation reasonCodes defined in https://tools.ietf.org/html/rfc5280#section-5.3.1.
Possible values are 0 (unspecified), 1 (keyCompromise), 2 (cACompromise), 3 (affiliationChanged), 4 (superseded), 5 (cessationOfOperation), 6 (certificateHold), 8 (removeFromCRL), 9 (privilegeWithdrawn), 10 (aACompromise)
validate_certs
bool

(added in 2.5)
    Choices:
  • no
  • yes ←
Whether calls to the ACME directory will validate TLS certificates.
Warning: Should only ever be set to no for testing purposes, for example when testing against a local Pebble server.

Examples

- name: Revoke certificate with account key
  acme_certificate_revoke:
    account_key_src: /etc/pki/cert/private/account.key
    certificate: /etc/httpd/ssl/sample.com.crt

- name: Revoke certificate with certificate's private key
  acme_certificate_revoke:
    private_key_src: /etc/httpd/ssl/sample.com.key
    certificate: /etc/httpd/ssl/sample.com.crt

Status

This module is flagged as preview which means that it is not guaranteed to have a backwards compatible interface.

Author

  • Felix Fontein (@felixfontein)

Hint

If you notice any issues in this documentation you can edit this document to improve it.