Execution
Date 15 Dec 2025 09:38:00 +0000
Duration 00:17:22.68
Controller aio1.openstack.local
User root
Versions
Ansible 2.18.6
ara 1.7.4 / 1.7.4
Python 3.12.3
Summary
18 Hosts
603 Tasks
2798 Results
18 Plays
138 Files
0 Records

Task result details

  • Status
    CHANGED
  • Duration
    00:00:01.83
  • Play
    Create CA certificates
  • Task
    pki : Sign the intermediate CA CSR for ExampleCorpIntermediate
  • Host
    localhost ( task delegated to localhost )

Field Value
ca_cert
/etc/openstack_deploy/pki/roots/ExampleCorpRoot/certs/ExampleCorpRoot.crt
ca_privatekey
/etc/openstack_deploy/pki/roots/ExampleCorpRoot/private/ExampleCorpRoot.key.pem
changed
True
csr
/etc/openstack_deploy/pki/roots/ExampleCorpIntermediate/csr/ca_csr-1000.csr
diff
--- before

+++ after

@@ -1 +1,107 @@

-{}
+{
+    "authority_cert_issuer": null,
+    "authority_cert_serial_number": null,
+    "authority_key_identifier": "95:37:ab:09:40:31:b1:0d:64:12:fe:a6:a7:51:3d:c2:40:28:39:58",
+    "basic_constraints": [
+        "CA:TRUE",
+        "pathlen:0"
+    ],
+    "basic_constraints_critical": true,
+    "can_parse_certificate": true,
+    "expired": false,
+    "extended_key_usage": null,
+    "extended_key_usage_critical": false,
+    "extensions_by_oid": {
+        "2.5.29.14": {
+            "critical": false,
+            "value": "BBQ5hlMthvwpPY3cdQ9jePY/kvPjMw=="
+        },
+        "2.5.29.15": {
+            "critical": false,
+            "value": "AwIBhg=="
+        },
+        "2.5.29.17": {
+            "critical": false,
+            "value": "MDeCNUV4YW1wbGUgQ29ycCBPcGVuc3RhY2sgSW5mcmFzdHJ1Y3R1cmUgSW50ZXJtZWRpYXRlIENB"
+        },
+        "2.5.29.19": {
+            "critical": true,
+            "value": "MAYBAf8CAQA="
+        },
+        "2.5.29.35": {
+            "critical": false,
+            "value": "MBaAFJU3qwlAMbENZBL+pqdRPcJAKDlY"
+        }
+    },
+    "fingerprints": {
+        "sha256": "69:8b:0e:05:c4:69:15:f4:75:f5:39:1c:13:af:29:0a:88:9a:ca:fc:64:39:4f:1d:d2:9e:c7:ce:b1:1f:5a:4e"
+    },
+    "issuer": {
+        "commonName": "Example Corp Root CA",
+        "countryName": "GB",
+        "stateOrProvinceName": "England"
+    },
+    "issuer_ordered": [
+        [
+            "countryName",
+            "GB"
+        ],
+        [
+            "stateOrProvinceName",
+            "England"
+        ],
+        [
+            "commonName",
+            "Example Corp Root CA"
+        ]
+    ],
+    "issuer_uri": null,
+    "key_usage": [
+        "CRL Sign",
+        "Certificate Sign",
+        "Digital Signature"
+    ],
+    "key_usage_critical": false,
+    "not_after": "20351213093843Z",
+    "not_before": "20251215093843Z",
+    "ocsp_must_staple": null,
+    "ocsp_must_staple_critical": false,
+    "ocsp_uri": null,
+    "public_key": "-----BEGIN PUBLIC KEY-----\nMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAoGq90ZHc0w0i+l+V7irf\ngSH7tuvPzxJCA+RUhDr2hhwkqOZg8TzhlX31AHq4DtlEp+G/2KwtzdX1XzApRijf\nLR9k3rsvAWl9jN+F5qIoWoC9V95ImUlQocszOPTlB/XmzIj/7XtbsK6YbT/IRO5h\nH1h2QpUR4ZHwxXDxX9aB8aCDk4TRyIDaTb/04cyZepmJcvzyazmKq4ryZFZ9i2eu\nd1nbI9ZCDq5RSUptuGm5kZWngRA5SYGOPNf6yD/pe3EnPnq7JJc0FR8+B6Wzks+2\nKPx4lL5zYmoCGHICRlnBEM+zGn5Bn9rfH+htpDLjyjgGi7xSwjV/XjRpnrYWTm/j\nBcx4Knq1IPXeG7fNE4B50VGB92OV+RaSKHiUOUmDCST38EH73J/GrQvyB7kM3DNX\n6ZkxcVxVTa764MPcrWRYfeCBJwx5kPZe2UIUebUZHzWxRvuilP2hT6v6PSZZl3FF\n9vGB3ohfyoKPD5sd4ftrIxFTpcHqM87A8uXzxuMyXW8jia1FA8BbGfZ/Bsdh7O7p\n2uA0SeXgaJCHUm/H9BripVlNhmDa0HOfoaxqlOr8/ICX3D25qZ787cjGyRAC7Vr9\niSZOe9D8GfSAofrLsBH3a9+6OWJhsR0cj9abBcU0WlCGkyskRWIw3YKdVPDO2m3B\nmaaQew5s/oV/KE+bGcH5V/0CAwEAAQ==\n-----END PUBLIC KEY-----\n",
+    "public_key_data": {
+        "exponent": 65537,
+        "modulus": 654444094796269234990640795429689516047206889286592340561600264260394895529580380539075973437705771318784098928616841375055758642767728482847544683744667654752509714562931008903622975546722655729195593682252855065470047153709924781195824675808889765127956273325524296234646956988117220685818972391759154785560086277074532615991416131499037190780073232055654040581499631977818641565287627466117981530223052034986669421536250289141285890331298857638117549451568096534117608132287656995798434182954590439754700039192556792444089899000153784050012625137994850253568784746449098680505740439789818246041795534925861457408832737379668124069075430403075612247501864937489449676887622931036568228055328289490466628031234479560958865259301422350106729815457498747023242638457572069734399838117831942417142396885259756736808440257829803723475873958142468698793964924506907791183676348032479031700910600488428949749324060136583263709865674556913417557671042749362215808380896856807926750704453611152767935022766947770055063210983915102330919460148022152244301026644399787448401349651036012471384196261100338226869682544891861696061750693841392221808035609595587676883993195617064462241088022077807424651965677499453196439313671076758379275311101,
+        "size": 4096
+    },
+    "public_key_fingerprints": {
+        "sha256": "cd:d8:85:8a:bc:56:ae:c3:32:b5:46:94:fb:43:43:51:eb:17:03:3c:1c:6d:d3:51:f8:fb:61:16:cd:94:88:46"
+    },
+    "public_key_type": "RSA",
+    "serial_number": 57083305037138034117952600552072823336706905064,
+    "signature_algorithm": "sha256WithRSAEncryption",
+    "subject": {
+        "commonName": "Example Corp Openstack Infrastructure Intermediate CA",
+        "countryName": "GB",
+        "stateOrProvinceName": "England"
+    },
+    "subject_alt_name": [
+        "DNS:Example Corp Openstack Infrastructure Intermediate CA"
+    ],
+    "subject_alt_name_critical": false,
+    "subject_key_identifier": "39:86:53:2d:86:fc:29:3d:8d:dc:75:0f:63:78:f6:3f:92:f3:e3:33",
+    "subject_ordered": [
+        [
+            "countryName",
+            "GB"
+        ],
+        [
+            "stateOrProvinceName",
+            "England"
+        ],
+        [
+            "commonName",
+            "Example Corp Openstack Infrastructure Intermediate CA"
+        ]
+    ],
+    "version": 3
+}
filename
/etc/openstack_deploy/pki/roots/ExampleCorpIntermediate/certs/ExampleCorpIntermediate-1000.crt
invocation
{
    "module_args": {
        "acme_accountkey_path": null,
        "acme_chain": false,
        "acme_challenge_path": null,
        "acme_directory": "https://acme-v02.api.letsencrypt.org/directory",
        "attributes": null,
        "backup": true,
        "csr_content": null,
        "csr_path": "/etc/openstack_deploy/pki/roots/ExampleCorpIntermediate/csr/ca_csr-1000.csr",
        "entrust_api_client_cert_key_path": null,
        "entrust_api_client_cert_path": null,
        "entrust_api_key": null,
        "entrust_api_specification_path": "https://cloud.entrust.net/EntrustCloud/documentation/cms-api-2.1.0.yaml",
        "entrust_api_user": null,
        "entrust_cert_type": "STANDARD_SSL",
        "entrust_not_after": "+365d",
        "entrust_requester_email": null,
        "entrust_requester_name": null,
        "entrust_requester_phone": null,
        "force": false,
        "group": null,
        "ignore_timestamps": true,
        "mode": null,
        "ownca_content": null,
        "ownca_create_authority_key_identifier": true,
        "ownca_create_subject_key_identifier": "create_if_not_provided",
        "ownca_digest": "sha256",
        "ownca_not_after": "+3650d",
        "ownca_not_before": "+0s",
        "ownca_path": "/etc/openstack_deploy/pki/roots/ExampleCorpRoot/certs/ExampleCorpRoot.crt",
        "ownca_privatekey_content": null,
        "ownca_privatekey_passphrase": null,
        "ownca_privatekey_path": "/etc/openstack_deploy/pki/roots/ExampleCorpRoot/private/ExampleCorpRoot.key.pem",
        "ownca_version": 3,
        "owner": null,
        "path": "/etc/openstack_deploy/pki/roots/ExampleCorpIntermediate/certs/ExampleCorpIntermediate-1000.crt",
        "privatekey_content": null,
        "privatekey_passphrase": null,
        "privatekey_path": null,
        "provider": "ownca",
        "return_content": false,
        "select_crypto_backend": "auto",
        "selevel": null,
        "selfsigned_create_subject_key_identifier": "create_if_not_provided",
        "selfsigned_digest": "sha256",
        "selfsigned_not_after": "+3650d",
        "selfsigned_not_before": "+0s",
        "selfsigned_version": 3,
        "serole": null,
        "setype": null,
        "seuser": null,
        "state": "present",
        "unsafe_writes": false
    }
}
notAfter
20351213093843Z
notBefore
20251215093843Z
privatekey None
serial_number
57083305037138034117952600552072823336706905064