File tree Expand file tree Collapse file tree 3 files changed +14
-8
lines changed
etc/kayobe/inventory/group_vars/all Expand file tree Collapse file tree 3 files changed +14
-8
lines changed Original file line number Diff line number Diff line change @@ -19,8 +19,8 @@ seed_openbao_pki_role_name: "ServerCert"
19
19
seed_openbao_pki_roles :
20
20
- name : " {{ seed_openbao_pki_role_name }}"
21
21
config :
22
- max_ttl : 8760h
23
- ttl : 8760h
22
+ max_ttl : 730d
23
+ ttl : 730d
24
24
allow_any_name : true
25
25
allow_ip_sans : true
26
26
require_cn : false
@@ -59,8 +59,8 @@ overcloud_openbao_pki_external_tls_role_name: "{{ overcloud_openbao_pki_default_
59
59
overcloud_openbao_pki_roles :
60
60
- name : " {{ overcloud_openbao_pki_default_role_name }}"
61
61
config :
62
- max_ttl : 8760h
63
- ttl : 8760h
62
+ max_ttl : 730d
63
+ ttl : 730d
64
64
allow_any_name : true
65
65
allow_ip_sans : true
66
66
require_cn : false
Original file line number Diff line number Diff line change @@ -25,8 +25,8 @@ seed_vault_pki_role_name: "ServerCert"
25
25
seed_vault_pki_roles:
26
26
- name: "{{ seed_vault_pki_role_name }}"
27
27
config:
28
- max_ttl: 8760h
29
- ttl: 8760h
28
+ max_ttl: 730d
29
+ ttl: 730d
30
30
allow_any_name: true
31
31
allow_ip_sans: true
32
32
require_cn: false
@@ -71,8 +71,8 @@ overcloud_vault_pki_external_tls_role_name: "{{ overcloud_vault_pki_default_role
71
71
overcloud_vault_pki_roles:
72
72
- name: "{{ overcloud_vault_pki_default_role_name }}"
73
73
config:
74
- max_ttl: 8760h
75
- ttl: 8760h
74
+ max_ttl: 730d
75
+ ttl: 730d
76
76
allow_any_name: true
77
77
allow_ip_sans: true
78
78
require_cn: false
Original file line number Diff line number Diff line change
1
+ ---
2
+ features :
3
+ - |
4
+ Increase the ``ttl`` of the ``PKI`` role to two years providing
5
+ the opportunity to replace ``internal`` and ``backend`` certificates
6
+ during the annual upgrade.
You can’t perform that action at this time.
0 commit comments