--- Exec[create chained cert /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chain.pem].orig
+++ Exec[create chained cert /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chain.pem]
+ subscribe => ['Exec[renew certificate - discovery2026__ganeti-test01_svc_codfw_wmnet]', 'File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chain.pem]', 'File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.pem]']
+ require => Exec[Generate cert discovery2026__ganeti-test01_svc_codfw_wmnet refresh on intermediate ca change]
+ notify => ['Service[ganeti]']
+ command => /bin/cat /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.pem /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chain.pem > /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chained.pem
+ unless => /usr/bin/test "$(/bin/cat /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.pem /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chain.pem | sha512sum)" == "$(/bin/cat /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chained.pem | sha512sum)"
File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet-key.pem]
- Parameters differences:
--- File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet-key.pem].orig
+++ File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet-key.pem]
- show_diff => False
- backup => False
- ensure => file
- owner => root
- group => gnt-admin
- mode => 0440
- File[/etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr]
- Parameters differences:
--- File[/etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr].orig
+++ File[/etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr]
+ mode => 0400
+ group => root
+ ensure => file
+ owner => root
- Content differences:
--- /etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr.orig
+++ /etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr
@@ -0,0 +1,13 @@
+{
+ "CN": "ganeti-test01.svc.codfw.wmnet",
+ "hosts": [
+ "ganeti-test01.svc.codfw.wmnet"
+ ],
+ "key": {
+ "algo": "ecdsa",
+ "size": 256
+ },
+ "names": [
+
+ ]
+}
- Cfssl::Csr[/etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr]
- Parameters differences:
--- Cfssl::Csr[/etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr].orig
+++ Cfssl::Csr[/etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr]
+ key => {'algo': 'ecdsa', 'size': 256}
+ names => []
+ ensure => present
+ hosts => []
+ common_name => ganeti-test01.svc.codfw.wmnet
- File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chained.pem]
- Parameters differences:
--- File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chained.pem].orig
+++ File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chained.pem]
- require => Exec[create chained cert /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chain.pem]
- group => gnt-admin
- ensure => file
- owner => root
- Exec[renew certificate - discovery2026__ganeti-test01_svc_codfw_wmnet]
- Parameters differences:
--- Exec[renew certificate - discovery2026__ganeti-test01_svc_codfw_wmnet].orig
+++ Exec[renew certificate - discovery2026__ganeti-test01_svc_codfw_wmnet]
+ environment => ['GODEBUG=x509ignoreCN=0']
+ require => Exec[Generate cert discovery2026__ganeti-test01_svc_codfw_wmnet]
+ notify => ['Service[ganeti]']
+ command => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ganeti-test2001.codfw.wmnet.pem -label discovery2026 /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.csr | /usr/bin/cfssljson -bare /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet
+ unless => /usr/bin/openssl x509 -in /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.pem -checkend 952200
- Exec[create chained cert /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chain.pem]
- Parameters differences:
--- Exec[create chained cert /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chain.pem].orig
+++ Exec[create chained cert /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chain.pem]
- subscribe => ['Exec[renew certificate - discovery__ganeti-test01_svc_codfw_wmnet]', 'File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chain.pem]', 'File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.pem]']
- require => Exec[Generate cert discovery__ganeti-test01_svc_codfw_wmnet refresh on intermediate ca change]
- notify => ['Service[ganeti]']
- command => /bin/cat /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.pem /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chain.pem > /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chained.pem
- unless => /usr/bin/test "$(/bin/cat /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.pem /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chain.pem | sha512sum)" == "$(/bin/cat /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.chained.pem | sha512sum)"
- File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.csr]
- Parameters differences:
--- File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.csr].orig
+++ File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.csr]
+ mode => 0440
+ group => gnt-admin
+ ensure => file
+ owner => root
- File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.pem]
- Parameters differences:
--- File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.pem].orig
+++ File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.pem]
+ mode => 0440
+ group => gnt-admin
+ ensure => file
+ owner => root
- Cfssl::Csr[/etc/cfssl/csr/discovery__ganeti-test01_svc_codfw_wmnet.csr]
- Parameters differences:
--- Cfssl::Csr[/etc/cfssl/csr/discovery__ganeti-test01_svc_codfw_wmnet.csr].orig
+++ Cfssl::Csr[/etc/cfssl/csr/discovery__ganeti-test01_svc_codfw_wmnet.csr]
- key => {'algo': 'ecdsa', 'size': 256}
- names => []
- ensure => present
- hosts => []
- common_name => ganeti-test01.svc.codfw.wmnet
- Exec[renew certificate - discovery__ganeti-test01_svc_codfw_wmnet]
- Parameters differences:
--- Exec[renew certificate - discovery__ganeti-test01_svc_codfw_wmnet].orig
+++ Exec[renew certificate - discovery__ganeti-test01_svc_codfw_wmnet]
- environment => ['GODEBUG=x509ignoreCN=0']
- require => Exec[Generate cert discovery__ganeti-test01_svc_codfw_wmnet]
- notify => ['Service[ganeti]']
- command => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ganeti-test2001.codfw.wmnet.pem -label discovery /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.csr | /usr/bin/cfssljson -bare /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet
- unless => /usr/bin/openssl x509 -in /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.pem -checkend 952200
- File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet-key.pem]
- Parameters differences:
--- File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet-key.pem].orig
+++ File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet-key.pem]
+ show_diff => False
+ backup => False
+ ensure => file
+ owner => root
+ group => gnt-admin
+ mode => 0440
- Exec[Generate cert discovery2026__ganeti-test01_svc_codfw_wmnet refresh on intermediate ca change]
- Parameters differences:
--- Exec[Generate cert discovery2026__ganeti-test01_svc_codfw_wmnet refresh on intermediate ca change].orig
+++ Exec[Generate cert discovery2026__ganeti-test01_svc_codfw_wmnet refresh on intermediate ca change]
+ subscribe => File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chain.pem]
+ environment => ['GODEBUG=x509ignoreCN=0']
+ require => Cfssl::Csr[/etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr]
+ notify => ['Service[ganeti]']
+ command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ganeti-test2001.codfw.wmnet.pem -label discovery2026 /etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr | /usr/bin/cfssljson -bare /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet
+ refreshonly => True
- Class[Profile::Ganeti]
- Parameters differences:
--- Class[Profile::Ganeti].orig
+++ Class[Profile::Ganeti]
@@
- cfssl_label => discovery
+ cfssl_label => discovery2026
- File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chain.pem]
- Parameters differences:
--- File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chain.pem].orig
+++ File[/etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.chain.pem]
+ source => puppet:///modules/profile/pki/intermediates/discovery2026-cert.pem
+ ensure => file
+ owner => root
+ group => gnt-admin
+ mode => 0440
- Cfssl::Cert[discovery2026__ganeti-test01_svc_codfw_wmnet]
- Parameters differences:
--- Cfssl::Cert[discovery2026__ganeti-test01_svc_codfw_wmnet].orig
+++ Cfssl::Cert[discovery2026__ganeti-test01_svc_codfw_wmnet]
+ common_name => ganeti-test01.svc.codfw.wmnet
+ notify_services => ['ganeti']
+ renew_seconds => 952200
+ owner => root
+ auto_renew => True
+ label => discovery2026
+ names => []
+ before_services => []
+ environment => ['GODEBUG=x509ignoreCN=0']
+ provide_chain => True
+ key => {'algo': 'ecdsa', 'size': 256}
+ ensure => present
+ hosts => []
+ outdir => /etc/ganeti/ssl
+ group => gnt-admin
+ mode => 0740
- Exec[Generate cert discovery2026__ganeti-test01_svc_codfw_wmnet]
- Parameters differences:
--- Exec[Generate cert discovery2026__ganeti-test01_svc_codfw_wmnet].orig
+++ Exec[Generate cert discovery2026__ganeti-test01_svc_codfw_wmnet]
+ environment => ['GODEBUG=x509ignoreCN=0']
+ require => Cfssl::Csr[/etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr]
+ notify => ['Service[ganeti]']
+ command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ganeti-test2001.codfw.wmnet.pem -label discovery2026 /etc/cfssl/csr/discovery2026__ganeti-test01_svc_codfw_wmnet.csr | /usr/bin/cfssljson -bare /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet
+ unless => /usr/bin/test "$(/usr/bin/openssl x509 -in /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet.pem -noout -pubkey 2>&1)" == "$(/usr/bin/openssl pkey -pubout -in /etc/ganeti/ssl/discovery2026__ganeti-test01_svc_codfw_wmnet-key.pem 2>&1)"
- Cfssl::Cert[discovery__ganeti-test01_svc_codfw_wmnet]
- Parameters differences:
--- Cfssl::Cert[discovery__ganeti-test01_svc_codfw_wmnet].orig
+++ Cfssl::Cert[discovery__ganeti-test01_svc_codfw_wmnet]
- common_name => ganeti-test01.svc.codfw.wmnet
- notify_services => ['ganeti']
- renew_seconds => 952200
- owner => root
- auto_renew => True
- label => discovery
- names => []
- before_services => []
- environment => ['GODEBUG=x509ignoreCN=0']
- provide_chain => True
- key => {'algo': 'ecdsa', 'size': 256}
- ensure => present
- hosts => []
- outdir => /etc/ganeti/ssl
- group => gnt-admin
- mode => 0740
- File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.pem]
- Parameters differences:
--- File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.pem].orig
+++ File[/etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet.pem]
- mode => 0440
- group => gnt-admin
- ensure => file
- owner => root
- Exec[Generate cert discovery__ganeti-test01_svc_codfw_wmnet refresh]
- Parameters differences:
--- Exec[Generate cert discovery__ganeti-test01_svc_codfw_wmnet refresh].orig
+++ Exec[Generate cert discovery__ganeti-test01_svc_codfw_wmnet refresh]
- subscribe => File[/etc/cfssl/csr/discovery__ganeti-test01_svc_codfw_wmnet.csr]
- environment => ['GODEBUG=x509ignoreCN=0']
- notify => ['Service[ganeti]']
- command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/ganeti-test2001.codfw.wmnet.pem -label discovery /etc/cfssl/csr/discovery__ganeti-test01_svc_codfw_wmnet.csr | /usr/bin/cfssljson -bare /etc/ganeti/ssl/discovery__ganeti-test01_svc_codfw_wmnet
- refreshonly => True