--- Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem].orig
+++ Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]
+ require => Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change]
+ command => /bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem > /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chained.pem
+ unless => /usr/bin/test "$(/bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem | sha512sum)" == "$(/bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chained.pem | sha512sum)"
+ subscribe => ['Exec[renew certificate - kafka__kafka_fundraising_client]', 'File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]', 'File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem]']
File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]
- Parameters differences:
--- File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr].orig
+++ File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]
+ ensure => file
+ group => root
+ mode => 0400
+ owner => root
- Content differences:
--- /etc/cfssl/csr/kafka__kafka_fundraising_client.csr.orig
+++ /etc/cfssl/csr/kafka__kafka_fundraising_client.csr
@@ -0,0 +1,13 @@
+{
+ "CN": "kafka_fundraising_client",
+ "hosts": [
+ "kafka_fundraising_client"
+ ],
+ "key": {
+ "algo": "ecdsa",
+ "size": 256
+ },
+ "names": [
+
+ ]
+}
- Cfssl::Cert[kafka__kafka_fundraising_client]
- Parameters differences:
--- Cfssl::Cert[kafka__kafka_fundraising_client].orig
+++ Cfssl::Cert[kafka__kafka_fundraising_client]
+ provide_chain => True
+ hosts => []
+ names => []
+ group => fr-tech-admins
+ mode => 0740
+ notify_services => []
+ ensure => present
+ label => kafka
+ key => {'algo': 'ecdsa', 'size': 256}
+ renew_seconds => 952200
+ auto_renew => True
+ before_services => []
+ outdir => /etc/fr-tech-kafka-client
+ environment => ['GODEBUG=x509ignoreCN=0']
+ common_name => kafka_fundraising_client
+ owner => root
- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem]
- Parameters differences:
--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem].orig
+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem]
+ ensure => file
+ group => fr-tech-admins
+ mode => 0440
+ owner => root
- Exec[Generate cert kafka__kafka_fundraising_client refresh]
- Parameters differences:
--- Exec[Generate cert kafka__kafka_fundraising_client refresh].orig
+++ Exec[Generate cert kafka__kafka_fundraising_client refresh]
+ refreshonly => True
+ command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka /etc/cfssl/csr/kafka__kafka_fundraising_client.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client
+ environment => ['GODEBUG=x509ignoreCN=0']
+ subscribe => File[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]
- Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]
- Parameters differences:
--- Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem].orig
+++ Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]
- require => Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh on intermediate ca change]
- command => /bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem > /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem
- unless => /usr/bin/test "$(/bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem | sha512sum)" == "$(/bin/cat /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem | sha512sum)"
- subscribe => ['Exec[renew certificate - kafka__kafka_fundraising_client_kafka_11]', 'File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]', 'File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.pem]']
- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.csr]
- Parameters differences:
--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.csr].orig
+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.csr]
- ensure => file
- group => fr-tech-admins
- mode => 0440
- owner => root
- Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change]
- Parameters differences:
--- Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change].orig
+++ Exec[Generate cert kafka__kafka_fundraising_client refresh on intermediate ca change]
+ refreshonly => True
+ require => Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]
+ command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka /etc/cfssl/csr/kafka__kafka_fundraising_client.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client
+ environment => ['GODEBUG=x509ignoreCN=0']
+ subscribe => File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]
- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11-key.pem]
- Parameters differences:
--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11-key.pem].orig
+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11-key.pem]
- owner => root
- ensure => file
- group => fr-tech-admins
- backup => False
- mode => 0440
- show_diff => False
- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem]
- Parameters differences:
--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem].orig
+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem]
+ owner => root
+ ensure => file
+ group => fr-tech-admins
+ backup => False
+ mode => 0440
+ show_diff => False
- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem]
- Parameters differences:
--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem].orig
+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chained.pem]
- require => Exec[create chained cert /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]
- ensure => file
- group => fr-tech-admins
- owner => root
- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]
- Parameters differences:
--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem].orig
+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.chain.pem]
+ source => puppet:///modules/profile/pki/intermediates/kafka-cert.pem
+ ensure => file
+ group => fr-tech-admins
+ mode => 0440
+ owner => root
- Exec[renew certificate - kafka__kafka_fundraising_client]
- Parameters differences:
--- Exec[renew certificate - kafka__kafka_fundraising_client].orig
+++ Exec[renew certificate - kafka__kafka_fundraising_client]
+ command => /usr/bin/cfssl sign -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client
+ environment => ['GODEBUG=x509ignoreCN=0']
+ unless => /usr/bin/openssl x509 -in /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem -checkend 952200
+ require => Exec[Generate cert kafka__kafka_fundraising_client]
- Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]
- Parameters differences:
--- Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr].orig
+++ Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]
- hosts => []
- key => {'algo': 'ecdsa', 'size': 256}
- names => []
- ensure => present
- common_name => kafka_fundraising_client
- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]
- Parameters differences:
--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem].orig
+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11.chain.pem]
- source => puppet:///modules/profile/pki/intermediates/kafka-cert.pem
- ensure => file
- group => fr-tech-admins
- mode => 0440
- owner => root
- Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh]
- Parameters differences:
--- Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh].orig
+++ Exec[Generate cert kafka__kafka_fundraising_client_kafka_11 refresh]
- refreshonly => True
- command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka -profile kafka_11 /etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client_kafka_11
- environment => ['GODEBUG=x509ignoreCN=0']
- subscribe => File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]
- File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]
- Parameters differences:
--- File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr].orig
+++ File[/etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr]
- ensure => file
- group => root
- mode => 0400
- owner => root
- Content differences:
--- /etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr.orig
+++ /etc/cfssl/csr/kafka__kafka_fundraising_client_kafka_11.csr
@@ -1,13 +0,0 @@
-{
- "CN": "kafka_fundraising_client",
- "hosts": [
- "kafka_fundraising_client"
- ],
- "key": {
- "algo": "ecdsa",
- "size": 256
- },
- "names": [
-
- ]
-}
- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr]
- Parameters differences:
--- File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr].orig
+++ File[/etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.csr]
+ ensure => file
+ group => fr-tech-admins
+ mode => 0440
+ owner => root
- Exec[Generate cert kafka__kafka_fundraising_client]
- Parameters differences:
--- Exec[Generate cert kafka__kafka_fundraising_client].orig
+++ Exec[Generate cert kafka__kafka_fundraising_client]
+ command => /usr/bin/cfssl gencert -config /etc/cfssl/client-cfssl.conf -tls-remote-ca /etc/ssl/certs/wmf-ca-certificates.crt -mutual-tls-client-cert /etc/cfssl/mutual_tls_client_cert.pem -mutual-tls-client-key /var/lib/puppet/ssl/private_keys/cumin1003.eqiad.wmnet.pem -label kafka /etc/cfssl/csr/kafka__kafka_fundraising_client.csr | /usr/bin/cfssljson -bare /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client
+ environment => ['GODEBUG=x509ignoreCN=0']
+ unless => /usr/bin/test "$(/usr/bin/openssl x509 -in /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client.pem -noout -pubkey 2>&1)" == "$(/usr/bin/openssl pkey -pubout -in /etc/fr-tech-kafka-client/kafka__kafka_fundraising_client-key.pem 2>&1)"
+ require => Cfssl::Csr[/etc/cfssl/csr/kafka__kafka_fundraising_client.csr]