[int]
This commit is contained in:
parent
4a7a75651c
commit
c4db57b83a
|
|
@ -1,4 +1,4 @@
|
||||||
{
|
{
|
||||||
"var_nginx_auto_reload_interval": null,
|
"var_nginx_auto_reload_interval": null,
|
||||||
"var_nginx_dhparam_size": 2048
|
"var_nginx_improved_security": false
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -13,8 +13,9 @@
|
||||||
{
|
{
|
||||||
"name": "generate dhparams file",
|
"name": "generate dhparams file",
|
||||||
"become": true,
|
"become": true,
|
||||||
|
"when": "var_nginx_improved_security",
|
||||||
"ansible.builtin.command": {
|
"ansible.builtin.command": {
|
||||||
"cmd": "openssl dhparam -out /etc/nginx/dhparam {{var_nginx_dhparam_size | string}}"
|
"cmd": "openssl dhparam -out /etc/nginx/dhparam 4096"
|
||||||
},
|
},
|
||||||
"args": {
|
"args": {
|
||||||
"creates": "/etc/nginx/dhparam"
|
"creates": "/etc/nginx/dhparam"
|
||||||
|
|
@ -22,6 +23,7 @@
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"name": "place hardening config",
|
"name": "place hardening config",
|
||||||
|
"when": "var_nginx_improved_security",
|
||||||
"become": true,
|
"become": true,
|
||||||
"ansible.builtin.copy": {
|
"ansible.builtin.copy": {
|
||||||
"src": "ssl-hardening.conf",
|
"src": "ssl-hardening.conf",
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue