Execution
Date
15 Dec 2025 09:38:00 +0000
Duration
00:17:22.68
Controller
aio1.openstack.local
User
root
Versions
Ansible
2.18.6
ara
1.7.4 / 1.7.4
Python
3.12.3
Summary
18
Hosts
603
Tasks
2798
Results
18
Plays
138
Files
0
Records
Task result details
-
StatusCHANGED
-
Duration00:00:01.91
-
PlayCreate CA certificates
-
Taskpki : Create the CA CSR for ExampleCorpRoot
-
Date15 Dec 2025 09:38:20 +0000
-
Module / Actioncommunity.crypto.openssl_csr (/home/zuul/src/opendev.org/openstack/ansible-role-pki/tasks/standalone/create_ca.yml:92)
-
Tags
- always
| Field | Value |
|---|---|
| basicConstraints |
[ "CA:TRUE" ] |
| changed |
True |
| diff |
--- before +++ after @@ -1 +1,72 @@ -{} +{ + "authority_cert_issuer": null, + "authority_cert_serial_number": null, + "authority_key_identifier": null, + "basic_constraints": [ + "CA:TRUE" + ], + "basic_constraints_critical": true, + "can_parse_csr": true, + "extended_key_usage": null, + "extended_key_usage_critical": false, + "extensions_by_oid": { + "2.5.29.15": { + "critical": false, + "value": "AwIBhg==" + }, + "2.5.29.17": { + "critical": false, + "value": "MBaCFEV4YW1wbGUgQ29ycCBSb290IENB" + }, + "2.5.29.19": { + "critical": true, + "value": "MAMBAf8=" + } + }, + "key_usage": [ + "CRL Sign", + "Certificate Sign", + "Digital Signature" + ], + "key_usage_critical": false, + "name_constraints_critical": false, + "name_constraints_excluded": null, + "name_constraints_permitted": null, + "ocsp_must_staple": null, + "ocsp_must_staple_critical": false, + "public_key": "-----BEGIN PUBLIC KEY-----\nMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA8jdm3piMsmOnGmSQr1Yq\n0UWgUHR5qBjtbvbiWYFI9VPmcXb0lLzpEjHip6JbRnWSwj+FXPW/sRYb+Yhbryro\nrLE0ToX3VQW87PTaYyhkUaeHJb+blHPKckIKIuLuPSOJ1G8kmiOWqI/dePMZ3Fxi\nDSqE5pwjTQgLz2wZSqAzDrn7u+S6yuJOGeeM7xkZqCGxRE0EKK6OI5beZ2ayEUke\nzmqfFjz5X+Z5p4VnTKUPK4re0rmTBQTXbjLA0KtliizzInCWX7OofxhjVDoLcr3l\n8aqESHNlQVxvHwBtP/Tbqeotw2rsF7VB5ENETTQkuZYghDXAteHACKVoTfly1dXN\n7X8/hWGerOxBe5B1ZWn1Da6fhmseO2S8xYS171ytkNmx8d7GsyY9Z7DRuYcTwxJg\naz8D4kSGr3c4xE3U+sPllwzf3d819Vf+KkSuBRoHWVygLYPiG0Noi3h622PvRQOC\nairF6fctmYalT71L6GI5aGb6YsCCjERTeBIuHO2FqH41q5dfbYu1oFOMdn/L3PF6\n1yRfjfdO24IOWOrK0NhYIn6hUAfCJxELyI4mImO+ONLysAlP5q30qi03eamUyFhE\ng+b9QVxY85l26S1czli/bMY4Leer0ax9iNRNssTN6qXwATOSgVarFbh3TvjdLboM\nf7DSJuvY/E8whhWB6mJezuUCAwEAAQ==\n-----END PUBLIC KEY-----\n", + "public_key_data": { + "exponent": 65537, + "modulus": 988156754162489372553334239501495963967961006181361207532302157332791085383807771423259007261747710961757032186698589664726690685003042879871436526615781127776225287185503975892253142415323074817389609483075415066991022089948737994967191524224323501115439325613796368341688780005991424196036767181623389075122278817077220919620145877839979625532752729857172929130877303529751025467955144250818444783354836880385944507027598426064446867401857054076563610775791880576623221786028085131092678754375985159240230985783167796677504372591585691219913316736799522253489637617240089202966231371429095827506058225396752676279010070136292778836891667325421522471929134549439124370922701619604528963207449683710362566622652679857388979538706348236337071790185815533115809404735847474905787205099786561184385577528902034998719069588210472825656851405756492011835637652959110498526627063392124540746758420061698355091524419367964840460571473920385226198099519251446390377425088889923680186878994142510385998535150128873808862334235653330604748803203757362369946313397089609443783272018695498337912448737920261297058146763236569451186150419144280571561988459865121862685369167898206866333793595851573367688393017278324630655550303314564109540708069, + "size": 4096 + }, + "public_key_fingerprints": { + "sha256": "9d:db:39:f7:07:29:37:ab:e7:46:5c:bd:ee:6d:29:06:e9:8b:75:56:c5:67:f9:56:02:22:27:f4:35:0a:af:fb" + }, + "public_key_type": "RSA", + "signature_valid": true, + "subject": { + "commonName": "Example Corp Root CA", + "countryName": "GB", + "stateOrProvinceName": "England" + }, + "subject_alt_name": [ + "DNS:Example Corp Root CA" + ], + "subject_alt_name_critical": false, + "subject_key_identifier": null, + "subject_ordered": [ + [ + "countryName", + "GB" + ], + [ + "stateOrProvinceName", + "England" + ], + [ + "commonName", + "Example Corp Root CA" + ] + ] +} |
| extendedKeyUsage | None |
| filename |
/etc/openstack_deploy/pki/roots/ExampleCorpRoot/csr/ca_csr-1000.csr |
| invocation |
{ "module_args": { "attributes": null, "authority_cert_issuer": null, "authority_cert_serial_number": null, "authority_key_identifier": null, "backup": true, "basic_constraints": [ "CA:TRUE" ], "basic_constraints_critical": true, "common_name": "Example Corp Root CA", "country_name": "GB", "create_subject_key_identifier": false, "crl_distribution_points": null, "digest": "sha256", "email_address": null, "extended_key_usage": null, "extended_key_usage_critical": false, "force": false, "group": null, "key_usage": [ "digitalSignature", "cRLSign", "keyCertSign" ], "key_usage_critical": false, "locality_name": null, "mode": null, "name_constraints_critical": false, "name_constraints_excluded": null, "name_constraints_permitted": null, "ocsp_must_staple": false, "ocsp_must_staple_critical": false, "organization_name": null, "organizational_unit_name": null, "owner": null, "path": "/etc/openstack_deploy/pki/roots/ExampleCorpRoot/csr/ca_csr-1000.csr", "privatekey_content": null, "privatekey_passphrase": null, "privatekey_path": "/etc/openstack_deploy/pki/roots/ExampleCorpRoot/private/ExampleCorpRoot.key.pem", "return_content": false, "select_crypto_backend": "auto", "selevel": null, "serole": null, "setype": null, "seuser": null, "state": "present", "state_or_province_name": "England", "subject": null, "subject_alt_name": null, "subject_alt_name_critical": false, "subject_key_identifier": null, "subject_ordered": null, "unsafe_writes": false, "use_common_name_for_san": true, "version": 1 } } |
| keyUsage |
[ "digitalSignature", "cRLSign", "keyCertSign" ] |
| name_constraints_excluded |
[]
|
| name_constraints_permitted |
[]
|
| ocspMustStaple |
False |
| privatekey |
/etc/openstack_deploy/pki/roots/ExampleCorpRoot/private/ExampleCorpRoot.key.pem |
| subject |
[ [ "C", "GB" ], [ "ST", "England" ], [ "CN", "Example Corp Root CA" ] ] |
| subjectAltName |
[ "DNS:Example Corp Root CA" ] |