Browse Source

Update ircbouncer role for LE certificate

Mike Ashley 9 years ago
parent
commit
ec7b5867d3
1 changed files with 6 additions and 4 deletions
  1. 6
    4
      roles/ircbouncer/tasks/znc.yml

+ 6
- 4
roles/ircbouncer/tasks/znc.yml View File

9
   group: name=znc state=present
9
   group: name=znc state=present
10
 
10
 
11
 - name: Create znc user
11
 - name: Create znc user
12
-  user: name=znc state=present home=/var/lib/znc system=yes group=znc shell=/usr/sbin/nologin
12
+  user: name=znc state=present home=/usr/lib/znc system=yes group=znc shell=/usr/sbin/nologin
13
 
13
 
14
 - name: Ensure pid directory exists
14
 - name: Ensure pid directory exists
15
   file: state=directory path=/var/run/znc group=znc owner=znc
15
   file: state=directory path=/var/run/znc group=znc owner=znc
17
 - name: Copy znc service file into place
17
 - name: Copy znc service file into place
18
   copy: src=etc_systemd_system_znc.service dest=/etc/systemd/system/znc.service mode=0644
18
   copy: src=etc_systemd_system_znc.service dest=/etc/systemd/system/znc.service mode=0644
19
 
19
 
20
-- name: Create a combined version of the private key with public cert and intermediate + root CAs
21
-  shell: cat /etc/ssl/private/wildcard_private.key /etc/ssl/certs/wildcard_combined.pem >
22
-    /usr/lib/znc/znc.pem creates=/usr/lib/znc/znc.pem
20
+- name: Create a combined version of the SSL private key and full certificate chain
21
+  shell: cat /etc/letsencrypt/live/{{ domain }}/privkey.pem
22
+    /etc/letsencrypt/live/{{ domain }}/fullchain.pem >
23
+    /usr/lib/znc/znc.pem
24
+    creates=/usr/lib/znc/znc.pem
23
   notify: restart znc
25
   notify: restart znc
24
 
26
 
25
 - name: Ensure znc user and group can read cert
27
 - name: Ensure znc user and group can read cert

Loading…
Cancel
Save