diff --git a/roles/web/files/certs b/roles/web/files/certs index 2ab89be..7181b3d 100644 --- a/roles/web/files/certs +++ b/roles/web/files/certs @@ -41,17 +41,3 @@ www.makerspace-regensburg.de: perm: '400' format: key action: '/usr/sbin/service nginx restart' - -www.plk-regensburg.de plk-regensburg.de: -- path: /etc/nginx/ssl/plk-regensburg.de.key - user: root - group: root - perm: '400' - format: key - action: '/usr/sbin/service nginx restart' -- path: /etc/nginx/ssl/plk-regensburg.de.crt - user: root - group: root - perm: '400' - format: crt,ca - action: '/usr/sbin/service nginx restart' diff --git a/roles/web/files/vhost b/roles/web/files/vhost index 5e34252..c6e4274 100644 --- a/roles/web/files/vhost +++ b/roles/web/files/vhost @@ -144,33 +144,3 @@ server { default_type text/html; } - -server { - listen 80; - listen [::]:80; - - server_name plk-regensburg.de www.plk-regensburg.de; - - location /.well-known/acme-challenge { - default_type "text/plain"; - alias /var/www/acme-challenge; - } - - location / { - return 301 https://www.plk-regensburg.de$request_uri; - } -} - -server { - listen 443 ssl http2; - listen [::]:443 ssl http2; - - server_name www.plk-regensburg.de; - - ssl_certificate_key /etc/nginx/ssl/www.plk-regensburg.de.key; - ssl_certificate /etc/nginx/ssl/www.plk-regensburg.de.crt; - - location / { - return 302 https://xn--bauwrts-8wa.de/prinzleokultur/; - } -} diff --git a/roles/web/tasks/main.yml b/roles/web/tasks/main.yml index 0078507..f02eef6 100644 --- a/roles/web/tasks/main.yml +++ b/roles/web/tasks/main.yml @@ -23,10 +23,6 @@ command: openssl req -x509 -nodes -newkey rsa:2048 -keyout /etc/nginx/ssl/www.makerspace-regensburg.de.key -out /etc/nginx/ssl/www.makerspace-regensburg.de.crt -days 730 -subj "/CN=www.makerspace-regensburg.de" creates=/etc/nginx/ssl/www.makerspace-regensburg.de.crt notify: Restart nginx -- name: Ensure (PLK) certificates are available - command: openssl req -x509 -nodes -newkey rsa:2048 -keyout /etc/nginx/ssl/www.plk-regensburg.de.key -out /etc/nginx/ssl/www.plk-regensburg.de.crt -days 730 -subj "/CN=www.plk-regensburg.de" creates=/etc/nginx/ssl/www.plk-regensburg.de.crt - notify: Restart nginx - - name: Configure certificate manager copy: src=certs dest=/etc/acertmgr/www.binary-kitchen.de.conf notify: Run acertmgr