<feed xmlns='http://www.w3.org/2005/Atom'>
<title>fripost-ansible/certs/public, branch master</title>
<subtitle>Fripost ansible scripts</subtitle>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/'/>
<entry>
<title>Define new host "calima" serving Nextcloud.</title>
<updated>2018-12-03T02:43:48+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2018-12-03T02:37:19+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=5ad9fc5e963b9a461f60799d7f185a9e2e13522f'/>
<id>5ad9fc5e963b9a461f60799d7f185a9e2e13522f</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>nginx: Don't hard-code the HPKP headers.</title>
<updated>2016-07-12T01:10:33+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-07-12T01:10:33+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=ef430522256013665205cdda05636846cc622251'/>
<id>ef430522256013665205cdda05636846cc622251</id>
<content type='text'>
Instead, lookup the pubkeys and compute the digests on the fly.  But
never modify the actual header snippet to avoid locking our users out.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Instead, lookup the pubkeys and compute the digests on the fly.  But
never modify the actual header snippet to avoid locking our users out.
</pre>
</div>
</content>
</entry>
<entry>
<title>Change the pubkey extension from .pem to .pub.</title>
<updated>2016-07-09T23:16:00+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-07-09T23:16:00+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=02772c92ce74490ce60792b0543d60ce71f28e42'/>
<id>02772c92ce74490ce60792b0543d60ce71f28e42</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>certs/public: fetch each cert's pubkey (SPKI), not the cert itself.</title>
<updated>2016-06-15T16:13:09+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-06-15T16:08:48+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=02d4a5892bb3019d448c453ad279788fcd3f1531'/>
<id>02d4a5892bb3019d448c453ad279788fcd3f1531</id>
<content type='text'>
To avoid new commits upon cert renewal.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
To avoid new commits upon cert renewal.
</pre>
</div>
</content>
</entry>
<entry>
<title>Renew cert for https://lists.fripost.org.</title>
<updated>2016-05-28T11:31:42+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-05-28T11:31:42+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=4872fcd0b60b21d6b016a9e2673e5662313815cb'/>
<id>4872fcd0b60b21d6b016a9e2673e5662313815cb</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Add an ansible module 'fetch_cmd' to fetch the output of a remote command locally.</title>
<updated>2016-05-17T22:47:05+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-05-17T22:10:50+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=71aefcc229f999f92b25e51b9444b313d95fbc86'/>
<id>71aefcc229f999f92b25e51b9444b313d95fbc86</id>
<content type='text'>
And use this to fetch all X.509 leaf certificates.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
And use this to fetch all X.509 leaf certificates.
</pre>
</div>
</content>
</entry>
<entry>
<title>Renew imap.fripost.org:993 and smtp.fripost.org:587 X.509 certificates.</title>
<updated>2016-05-17T22:06:54+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-05-17T22:06:23+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=f4c280d1c6f43f7ca0c1e498ab87fe7aa08d5eb2'/>
<id>f4c280d1c6f43f7ca0c1e498ab87fe7aa08d5eb2</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Reissue certs on civett and elefant since LE's X3 intermediate CA has better support for XP.</title>
<updated>2016-03-27T17:19:01+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-03-27T17:19:01+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=4dbc2fb82f4f001c4927d200ddedae7ac1ff5f70'/>
<id>4dbc2fb82f4f001c4927d200ddedae7ac1ff5f70</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Let's Encrypt: Only reload (as opposed to restart) postfix/nginx after renewing the cert</title>
<updated>2016-03-05T13:55:40+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-03-05T13:55:40+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=06f4a2e56948f0b2e2842a5ba5b9fe0d21bc8ba8'/>
<id>06f4a2e56948f0b2e2842a5ba5b9fe0d21bc8ba8</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Let's Encrypt</title>
<updated>2016-03-02T20:38:37+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-02-26T23:45:50+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=ed8cf1de7e87ff6496db46f17fb4bcfc90ccf48f'/>
<id>ed8cf1de7e87ff6496db46f17fb4bcfc90ccf48f</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
