adding preshared key generation

This commit is contained in:
elreydetoda 2019-06-02 05:03:42 -04:00 committed by GitHub
parent 2d04f65284
commit 8e5f0366cd
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -1,5 +1,5 @@
--- ---
- name: Delete the lock files - name: Delete the private lock files
file: file:
dest: "{{ config_prefix|default('/') }}etc/wireguard/private_{{ item }}.lock" dest: "{{ config_prefix|default('/') }}etc/wireguard/private_{{ item }}.lock"
state: absent state: absent
@ -8,6 +8,15 @@
- "{{ users }}" - "{{ users }}"
- "{{ IP_subject_alt_name }}" - "{{ IP_subject_alt_name }}"
- name: Delete the preshared lock files
file:
dest: "{{ config_prefix|default('/') }}etc/wireguard/preshared_{{ item }}.lock"
state: absent
when: keys_clean_all|bool
with_items:
- "{{ users }}"
- "{{ IP_subject_alt_name }}"
- name: Generate private keys - name: Generate private keys
command: wg genkey command: wg genkey
register: wg_genkey register: wg_genkey
@ -17,15 +26,26 @@
- "{{ users }}" - "{{ users }}"
- "{{ IP_subject_alt_name }}" - "{{ IP_subject_alt_name }}"
- name: Generate preshared keys
command: wg genpsk
register: wg_genpsk
args:
creates: "{{ config_prefix|default('/') }}etc/wireguard/preshared_{{ item }}.lock"
with_items:
- "{{ users }}"
- "{{ IP_subject_alt_name }}"
- block: - block:
- name: Save private keys - name: Save keys
copy: copy:
dest: "{{ wireguard_pki_path }}/private/{{ item['item'] }}" dest: "{{ wireguard_pki_path }}/private/{{ item['item'] }}"
content: "{{ item['stdout'] }}" content: "{{ item['stdout'] }}"
mode: "0600" mode: "0600"
no_log: true no_log: true
when: item.changed when: item.changed
with_items: "{{ wg_genkey['results'] }}" with_items:
- "{{ wg_genkey['results'] }}"
- "{{ wg_genpsk['results'] }}"
delegate_to: localhost delegate_to: localhost
become: false become: false
@ -38,6 +58,15 @@
- "{{ IP_subject_alt_name }}" - "{{ IP_subject_alt_name }}"
when: wg_genkey.changed when: wg_genkey.changed
- name: Touch the lock file
file:
dest: "{{ config_prefix|default('/') }}etc/wireguard/preshared_{{ item }}.lock"
state: touch
with_items:
- "{{ users }}"
- "{{ IP_subject_alt_name }}"
when: wg_preshared.changed
- name: Generate public keys - name: Generate public keys
shell: | shell: |
set -o pipefail set -o pipefail