Execution
Date 08 Dec 2025 13:27:39 +0000
Duration 00:05:33.94
Controller aio1.openstack.local
User root
Versions
Ansible 2.18.6
ara 1.7.4 / 1.7.4
Python 3.12.3
Summary
2 Hosts
316 Tasks
313 Results
18 Plays
136 Files
0 Records

Task result details

  • Status
    CHANGED
  • Duration
    00:00:01.86
  • Play
    Create CA certificates
  • Task
    pki : Sign the intermediate CA CSR for ExampleCorpIntermediate
  • Host
    localhost ( task delegated to localhost )

Field Value
ca_cert
/etc/openstack_deploy/pki/roots/ExampleCorpRoot/certs/ExampleCorpRoot.crt
ca_privatekey
/etc/openstack_deploy/pki/roots/ExampleCorpRoot/private/ExampleCorpRoot.key.pem
changed
True
csr
/etc/openstack_deploy/pki/roots/ExampleCorpIntermediate/csr/ca_csr-1000.csr
diff
--- before

+++ after

@@ -1 +1,107 @@

-{}
+{
+    "authority_cert_issuer": null,
+    "authority_cert_serial_number": null,
+    "authority_key_identifier": "94:88:4c:7a:3e:60:d3:ba:54:19:a8:4f:00:b2:19:53:c3:e2:b1:8e",
+    "basic_constraints": [
+        "CA:TRUE",
+        "pathlen:0"
+    ],
+    "basic_constraints_critical": true,
+    "can_parse_certificate": true,
+    "expired": false,
+    "extended_key_usage": null,
+    "extended_key_usage_critical": false,
+    "extensions_by_oid": {
+        "2.5.29.14": {
+            "critical": false,
+            "value": "BBQ7pMpfVdQnq8SNU1DrGWYigH5j5A=="
+        },
+        "2.5.29.15": {
+            "critical": false,
+            "value": "AwIBhg=="
+        },
+        "2.5.29.17": {
+            "critical": false,
+            "value": "MDeCNUV4YW1wbGUgQ29ycCBPcGVuc3RhY2sgSW5mcmFzdHJ1Y3R1cmUgSW50ZXJtZWRpYXRlIENB"
+        },
+        "2.5.29.19": {
+            "critical": true,
+            "value": "MAYBAf8CAQA="
+        },
+        "2.5.29.35": {
+            "critical": false,
+            "value": "MBaAFJSITHo+YNO6VBmoTwCyGVPD4rGO"
+        }
+    },
+    "fingerprints": {
+        "sha256": "2c:f0:9d:0e:35:f7:a5:bf:f0:01:3c:ff:e6:65:e4:5b:f5:4b:cf:d4:b8:ec:6d:cf:fc:31:79:1c:bf:b8:6e:53"
+    },
+    "issuer": {
+        "commonName": "Example Corp Root CA",
+        "countryName": "GB",
+        "stateOrProvinceName": "England"
+    },
+    "issuer_ordered": [
+        [
+            "countryName",
+            "GB"
+        ],
+        [
+            "stateOrProvinceName",
+            "England"
+        ],
+        [
+            "commonName",
+            "Example Corp Root CA"
+        ]
+    ],
+    "issuer_uri": null,
+    "key_usage": [
+        "CRL Sign",
+        "Certificate Sign",
+        "Digital Signature"
+    ],
+    "key_usage_critical": false,
+    "not_after": "20351206132822Z",
+    "not_before": "20251208132822Z",
+    "ocsp_must_staple": null,
+    "ocsp_must_staple_critical": false,
+    "ocsp_uri": null,
+    "public_key": "-----BEGIN PUBLIC KEY-----\nMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEApRYRMTi6YZWFoHvepZLa\nsnGhqJF3BfuW0YPWBKTeDVcx1Kwmu3uvZ/Pq+G1dHZ/zMy2rVSLfeIEAx/glSArx\n396unj9GO2EBNsAetAcj96O+b+KpVsh/A3c0S7PeDM0A1qGpHcE0eEP3Cy5kFbxH\n+D7Bts/ih/1j7/cLmSoDKXGcBtlmUuK0XmPNPIk61hG8gC3HUHpRazMqFCqFlJ6Z\nz4It0XngEtPBiLch0opaWcHy+W54AgUtMWEdJZOZN9Z9ShhGVVUpIicB2SszYw74\nKM7WNnNEjvtWsiqmYCjZhQnGCxAXSViEAqmi0iZex/2uuo+iM/odRR+EFZE/x0vv\nfKNqdSH/ecC1fDxdMpfT9dC06PlKzt47qVvHV8Yx0STUyG9KAZ/V9DJ6R+7rbt/5\n1ioNyQBlcvUoEDeJfOTaFC4tllwSylyhG01YYeo/ZgXzSNtiZCRhU4qCsWc6B5XO\n9LTSGErq/EgPg+Fbc1KQeJVgdbpkcdbxGhmK0voGZR7emUYB7MyDEuHmfAGQ2X+X\nb7vU86Mf1xn230qQIsnrAo+Ks1ORay29eoLkq1JHNZKWGHariP1rjTNhep/DVfmC\n0xY8DITeLQZ4DsFBG3MV2Smt82N26OGPVTJL0Ig4GvaN5w1XnMekFVnmoQnpY09d\ncy1paqf96jfI8ueJhuGJAPkCAwEAAQ==\n-----END PUBLIC KEY-----\n",
+    "public_key_data": {
+        "exponent": 65537,
+        "modulus": 673492935861702354079474614034877560273876392887336445148783510597132213557047296732210121548367604330295101357984404552573405309049337846318729314297431425013185559210367502614685343671125577218060273556235149863794513564278569851192622079037569467156719832932368326520986793858880963659326193883895610198812467666116674523777134722178008232371607848487556426498997571449564807689112375109364890654367831258808326334179932451205910936900785536578452802896755068634599271565490324689674686724000601610240770578834423818984927077118819896429032137515748779714243622260981653061603904553576656318619965925111228804953064758898446428342971503971802765664581220405837815581015691618301222481886251556661460078143355576525085163861465035646109608896872187082033979176026429049131948095219373390498385567558326295007172251735714351180214936477829126469039413109875815582835877849218641239202517133288674194791748353015653464817832449558838956985252322954859588065238032670982649659754978945633615062299825927268565297747760870753253141071508117404579673733874643941369354478396314252456611891868357946057131790569190042320403728622282315018021097305138059339535036582415512246575386602816779520037612191858664501236268528719528707626696953,
+        "size": 4096
+    },
+    "public_key_fingerprints": {
+        "sha256": "71:72:a8:e3:4b:5c:c6:0f:25:73:d1:9d:d6:c1:44:42:0f:50:f1:71:97:64:65:a4:12:22:38:ae:b9:13:07:b6"
+    },
+    "public_key_type": "RSA",
+    "serial_number": 729165944330368469259088645262192509208524202920,
+    "signature_algorithm": "sha256WithRSAEncryption",
+    "subject": {
+        "commonName": "Example Corp Openstack Infrastructure Intermediate CA",
+        "countryName": "GB",
+        "stateOrProvinceName": "England"
+    },
+    "subject_alt_name": [
+        "DNS:Example Corp Openstack Infrastructure Intermediate CA"
+    ],
+    "subject_alt_name_critical": false,
+    "subject_key_identifier": "3b:a4:ca:5f:55:d4:27:ab:c4:8d:53:50:eb:19:66:22:80:7e:63:e4",
+    "subject_ordered": [
+        [
+            "countryName",
+            "GB"
+        ],
+        [
+            "stateOrProvinceName",
+            "England"
+        ],
+        [
+            "commonName",
+            "Example Corp Openstack Infrastructure Intermediate CA"
+        ]
+    ],
+    "version": 3
+}
filename
/etc/openstack_deploy/pki/roots/ExampleCorpIntermediate/certs/ExampleCorpIntermediate-1000.crt
invocation
{
    "module_args": {
        "acme_accountkey_path": null,
        "acme_chain": false,
        "acme_challenge_path": null,
        "acme_directory": "https://acme-v02.api.letsencrypt.org/directory",
        "attributes": null,
        "backup": true,
        "csr_content": null,
        "csr_path": "/etc/openstack_deploy/pki/roots/ExampleCorpIntermediate/csr/ca_csr-1000.csr",
        "entrust_api_client_cert_key_path": null,
        "entrust_api_client_cert_path": null,
        "entrust_api_key": null,
        "entrust_api_specification_path": "https://cloud.entrust.net/EntrustCloud/documentation/cms-api-2.1.0.yaml",
        "entrust_api_user": null,
        "entrust_cert_type": "STANDARD_SSL",
        "entrust_not_after": "+365d",
        "entrust_requester_email": null,
        "entrust_requester_name": null,
        "entrust_requester_phone": null,
        "force": false,
        "group": null,
        "ignore_timestamps": true,
        "mode": null,
        "ownca_content": null,
        "ownca_create_authority_key_identifier": true,
        "ownca_create_subject_key_identifier": "create_if_not_provided",
        "ownca_digest": "sha256",
        "ownca_not_after": "+3650d",
        "ownca_not_before": "+0s",
        "ownca_path": "/etc/openstack_deploy/pki/roots/ExampleCorpRoot/certs/ExampleCorpRoot.crt",
        "ownca_privatekey_content": null,
        "ownca_privatekey_passphrase": null,
        "ownca_privatekey_path": "/etc/openstack_deploy/pki/roots/ExampleCorpRoot/private/ExampleCorpRoot.key.pem",
        "ownca_version": 3,
        "owner": null,
        "path": "/etc/openstack_deploy/pki/roots/ExampleCorpIntermediate/certs/ExampleCorpIntermediate-1000.crt",
        "privatekey_content": null,
        "privatekey_passphrase": null,
        "privatekey_path": null,
        "provider": "ownca",
        "return_content": false,
        "select_crypto_backend": "auto",
        "selevel": null,
        "selfsigned_create_subject_key_identifier": "create_if_not_provided",
        "selfsigned_digest": "sha256",
        "selfsigned_not_after": "+3650d",
        "selfsigned_not_before": "+0s",
        "selfsigned_version": 3,
        "serole": null,
        "setype": null,
        "seuser": null,
        "state": "present",
        "unsafe_writes": false
    }
}
notAfter
20351206132822Z
notBefore
20251208132822Z
privatekey None
serial_number
729165944330368469259088645262192509208524202920