Ansible roles by Evolix
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
Jérémy Lecour 7a9624fcc2 evoacme: remove shellcheck warnings 2 months ago
defaults evoacme: install hooks 2 years ago
files evoacme: remove shellcheck warnings 2 months ago
handlers Better squid/squid3 whitelist and reload 3 years ago
meta change repositories URL 1 year ago
tasks Replace version_compare() with version() 4 months ago
templates Replace version_compare() with version() 4 months ago
tests Add some kitchen tests for many roles 3 years ago
.kitchen.yml Kitchen: Change base image to evolix/ansible 3 years ago evoacme: upstream version 19.11 8 months ago

Evoacme 2.0

The upstream repository of EvoAcme is at

Shell scripts are copied from the upstream repository after each release. No changes must be applied directly here ; patch upstream, release then copy here.


1 - Create a playbook with evoacme role

- hosts: hostname
  become: yes
    - evoacme

2 - Install evoacme prerequisite with ansible

# ansible-playbook playbook.yml -K --limit hostname

3 - Include letsencrypt.conf in your webserver

For Apache, you just need to ensure that you don’t overwrite “/.well-known/acme-challenge” Alias with a Redirect or Rewrite directive.

For Nginx, you must include /etc/nginx/snippets/letsencrypt.conf in all wanted vhosts :

server {
    include /etc/nginx/snippets/letsencrypt.conf;

then reload the Nginx configuration :

# nginx -t
# service nginx reload

4 - Create a CSR for a vhost with make-csr

# make-csr vhostname domain...

5 - Generate the certificate with evoacme

# evoacme look for /etc/ssl/requests/vhostname
# vhostname was the same used by make-csr
evoacme vhostname

6 - Include ssl configuration

Sll configuration has generated, you must include it in your vhost.

For Apache :

Include /etc/apache2/ssl/vhost.conf

For Nginx :

include /etc/nginx/ssl/vhost.conf;