Remove keystone PKI cert generation
authorSteven Hardy <shardy@redhat.com>
Wed, 3 Aug 2016 12:37:53 +0000 (13:37 +0100)
committerSteven Hardy <shardy@redhat.com>
Fri, 5 Aug 2016 16:03:22 +0000 (17:03 +0100)
We don't currently offer any parameter interface to enable
PKI certs, and these have all been deprecated by keystone, so
remove them.

Change-Id: I8232262b928c91dcde7bea2f23fa2a7c2660719e

manifests/profile/base/keystone.pp
manifests/profile/pacemaker/keystone.pp

index 9617c11..bba98f8 100644 (file)
@@ -67,34 +67,6 @@ class tripleo::profile::base::keystone (
       include ::keystone::endpoint
     }
 
-    #TODO: need a cleanup-keystone-tokens.sh solution here
-    file { [ '/etc/keystone/ssl', '/etc/keystone/ssl/certs', '/etc/keystone/ssl/private' ]:
-      ensure  => 'directory',
-      owner   => 'keystone',
-      group   => 'keystone',
-      require => Package['keystone'],
-    }
-    file { '/etc/keystone/ssl/certs/signing_cert.pem':
-      content => hiera('keystone_signing_certificate'),
-      owner   => 'keystone',
-      group   => 'keystone',
-      notify  => Service[$::apache::params::service_name],
-      require => File['/etc/keystone/ssl/certs'],
-    }
-    file { '/etc/keystone/ssl/private/signing_key.pem':
-      content => hiera('keystone_signing_key'),
-      owner   => 'keystone',
-      group   => 'keystone',
-      notify  => Service[$::apache::params::service_name],
-      require => File['/etc/keystone/ssl/private'],
-    }
-    file { '/etc/keystone/ssl/certs/ca.pem':
-      content => hiera('keystone_ca_certificate'),
-      owner   => 'keystone',
-      group   => 'keystone',
-      notify  => Service[$::apache::params::service_name],
-      require => File['/etc/keystone/ssl/certs'],
-    }
   }
 
   if $step >= 5 and $manage_db_purge {
index 1cd5178..f48193a 100644 (file)
@@ -77,9 +77,6 @@ class tripleo::profile::pacemaker::keystone (
       require         => [Pacemaker::Resource::Ocf['rabbitmq'],
                           Pacemaker::Resource::Ocf['openstack-core']],
     }
-    File['/etc/keystone/ssl/certs/ca.pem'] -> Pacemaker::Resource::Service[$::apache::params::service_name]
-    File['/etc/keystone/ssl/private/signing_key.pem'] -> Pacemaker::Resource::Service[$::apache::params::service_name]
-    File['/etc/keystone/ssl/certs/signing_cert.pem'] -> Pacemaker::Resource::Service[$::apache::params::service_name]
   }
 
 }