An Ansible playbook generates the key pairs and the CSRs. Specifically:
- The key lives where the playbook determines it to. For example: a key manager, the host, or an HSM.
- Certificate Manager receives the CSR and issues the certificate.
- The user playbook deploys the certificate and the key.
This strategy requires the following settings.
Pre-issuance Playbook
Upload an Ansible playbook that runs on target hosts before certificate enrollment to:
- Generate a key pair and CSR
- Create directories or perform any pre-enrollment setup.
Specifically:
- If the bulk destination selected in Step 2 - Target does not set a Key Destination File Path, this playbook must handle key placement.
- The playbook must register the CSR PEM encoding in an Ansible variable for Certificate Manager to issue the certificate.
See Writing pre- and post-issuance playbooks for instructions on writing custom playbooks.
Mandatory: Yes.
CSR PEM Output Variable
The name of the Ansible variable in your Pre-issuance Playbook that holds the PEM encoding of the CSR. Certificate Manager will read this variable to issue the certificate. See the table below for examples.
Playbook definition | Variable name |
|---|---|
register: csr_pem | csr_pem |
set_fact: csr_pem: '{{ csr_output.stdout }}' | csr_pem |
Mandatory: Yes.
Pre-Issuance Extra Variables
The YAML or JSON specification of the variables required by the imported playbook
Mandatory: When the Pre-issuance Playbook requires variables that are not defined within the playbook itself.