From c3060daf924e444525c073f764611b2fe8da396a Mon Sep 17 00:00:00 2001 From: Henri Dohmen Date: Sat, 31 Jan 2026 13:09:05 +0100 Subject: [PATCH] git tls cert --- bin/gen-tls-cert | 2 +- pki/ca.cert | 34 +++++++++++++++++----------------- pki/server.cert | 36 ++++++++++++++++++------------------ secrets/tlskey.age | Bin 2246 -> 2246 bytes 4 files changed, 36 insertions(+), 36 deletions(-) diff --git a/bin/gen-tls-cert b/bin/gen-tls-cert index 35a9c1f..20b468b 100755 --- a/bin/gen-tls-cert +++ b/bin/gen-tls-cert @@ -19,7 +19,7 @@ openssl req -nodes \ | agenix -e secrets/tlskey.age cat > "$tmp/extfile" << EOF -subjectAltName=DNS:roam.lan,DNS:*.roam.lan +subjectAltName=DNS:roam.lan,DNS:*.roam.lan,DNS:git.lan authorityKeyIdentifier=keyid,issuer basicConstraints=CA:FALSE keyUsage=digitalSignature,keyEncipherment diff --git a/pki/ca.cert b/pki/ca.cert index 78901f9..aa19f71 100644 --- a/pki/ca.cert +++ b/pki/ca.cert @@ -1,19 +1,19 @@ -----BEGIN CERTIFICATE----- -MIIDBTCCAe2gAwIBAgIUQZNUMLFIGLdsj9Cj3a3TpX45Wv0wDQYJKoZIhvcNAQEL -BQAwEjEQMA4GA1UEAwwHaGRfcm9vdDAeFw0yNTEwMDQxMTU3NTdaFw0yNjEwMDQx -MTU3NTdaMBIxEDAOBgNVBAMMB2hkX3Jvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IB -DwAwggEKAoIBAQC7bpbr+iJ4O5asQmy3bP1xe0hgNkU3BqKGxFmQ5neKDMBEhnHt -ubb0jlPDns9reawX/2/7MGZFKTHvjlzZdKkSA+7t/afRs4O/sP3gqN0N7g6QdRGt -aC+7skib+tN1mrx7ZlL3UXhDE4iLhwff1PJdsGuwW3Kt4GoXISwaQlFrAhGNyuB9 -5ZQuGk4TySiBRsghg/Q54V7njl7Ob5XfH2MfgONPTpd7j58kA4g5Y5HJYK6THdzU -GZG5YrxWdmxRRhXC0LFPvS/QRc/HzvOdjryEgAQBl0VUNaU+hsd0smxNWFCbUIx3 -XafZXxlDGFnU8ktbkgHnMjlgbteBYxx9BB/BAgMBAAGjUzBRMB0GA1UdDgQWBBQM -lKKCnjZOHyPIm1peyUgQLErdRTAfBgNVHSMEGDAWgBQMlKKCnjZOHyPIm1peyUgQ -LErdRTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCMviNrad9B -I2XL3grAeyWAsbo9Ne4UApozzjInbX/fczxuP0QL9zSt6l3FVgN2HOnd56NjwSKF -LJyGJwjO+HoC6XDGIcMwFvch16FSTzuORKMCjWOXEq2ZFsbTa8fcSyfXRq+xcdc+ -lgaqsEMBaO3vi19nFxEOO7Ps467F46uHF8RuTCnslI0UCHWiHoOT0n0E7Pr++IX/ -bsVeL5xRKivi37JMAkAGWPH3qqpk4wh3dgLbPBcwDf/nf6ERS2yGtAF1Ucwpg/9W -7jvtw3TScoL4Fwl0X52aaF1WqRaS1Ovo3DLP8QfeyUVtDCxKdc+YgwXRJ963QDsX -Oj33DVkzEVG1 +MIIDBTCCAe2gAwIBAgIUOp5TCMV734ZH8n7S9qMstDeLUgAwDQYJKoZIhvcNAQEL +BQAwEjEQMA4GA1UEAwwHaGRfcm9vdDAeFw0yNjAxMzExMjA3MzhaFw0yNzAxMzEx +MjA3MzhaMBIxEDAOBgNVBAMMB2hkX3Jvb3QwggEiMA0GCSqGSIb3DQEBAQUAA4IB +DwAwggEKAoIBAQCry5pMvP7Bm3nypYbD4E1RR5Gyu2CkatkRSRBK39NvfkX7GOLJ +9bWDRDNUj6bw97ZyhCbw7ySV3KI5XfWfy9HWqJtEca3qGg0AwOxuke4Bhl11mb52 +RvU3y8qYLw5imvqKoX5iARmf+o6mk9cu0IFOTypRjgVEeTPM+i65qvwPs+estAl9 +bW7MrxN07hIzDvDWaXnYkIL+3TOXHq+zldD/5f5L17F3XHGUK2yKXBahcdcL2gdj +eXCb6mXdNmp6dD6CXVSY8EBFjoJyYHAfn13c3f29lIItQU2r8wWt/irNpf5pl7r2 +qyrzDB4q4L5QGhKkZhs05rU6YTReLPKAAl2XAgMBAAGjUzBRMB0GA1UdDgQWBBRk +r8YAWbZlBTwJQhL2gAyzEk/dhTAfBgNVHSMEGDAWgBRkr8YAWbZlBTwJQhL2gAyz +Ek/dhTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQA1LDP92xo4 +iOIvXZ0uVqR95/2QaB0zARvqP6nJ9XtfyyeDj8fF/iPz0/2FO8Svkba/5ZlEpr19 +49PQ1ufkCVhJTh1aCkJLjmiyYeBZXFRjbw7Tr3O9f9Pe8Ud01nwHyaLl3GHaacL1 +DGjSIpEbkS6zxDxfwhzqXnqKvT37Gcy+hpmMkRX7a3RyYg696azAd+bTjxKpCqmC +iL0YrH4cnQ8sbKklKNxjjRVAjzWQ7BhPcIXABauNgIOvHHDe7NWcAEMMca5Fcmja +tRsMLlfwyBM4YgRi9dq66C+LU+LuzBF5L0WTcwf8mXJDieE53A/4D0fig7+nkJrM +8sWed8nJa0FF -----END CERTIFICATE----- diff --git a/pki/server.cert b/pki/server.cert index 3e99c74..35c78dd 100644 --- a/pki/server.cert +++ b/pki/server.cert @@ -1,20 +1,20 @@ -----BEGIN CERTIFICATE----- -MIIDQDCCAiigAwIBAgIUNoexai8hK2EXKI7S0NuZFuhtVF0wDQYJKoZIhvcNAQEL -BQAwEjEQMA4GA1UEAwwHaGRfcm9vdDAeFw0yNTEwMDQxMTU3NTdaFw0yNjEwMDQx -MTU3NTdaMA4xDDAKBgNVBAMMA2xhbjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC -AQoCggEBAMY1qSgzUCcRRyJXsd+8KWRfPS4BMWXRKJwsH3RKXBEFVO5SZGynV5AD -W6sUw/2VeIW1LLhpt7AnEblJ0zVNcIcFyisAGQK0sLgSmPZ0q6j1MHXd37hVQ5GX -7DQ/ZMSPuOJgCpSjWVvCmnUOWlkZtqUpPKIxpHH5YsakbLorQgHiGYjiHeWJTqM7 -Ahi9IaMCRwgBK0G8TQ3jI2CUk1OxX4r48pxp7kR3u+rRLec5ZdzefMboyL6m9K4P -r3MA10uF8SvzEC9IH1PixGMgqW6iMBsscuNGMoWPf6MWnJwYr3DOe1B8G0VrFdZg -mENh84jJhPcKrHTsszdj8fkl0K30ezsCAwEAAaOBkTCBjjAfBgNVHREEGDAWgghy -b2FtLmxhboIKKi5yb2FtLmxhbjAfBgNVHSMEGDAWgBQMlKKCnjZOHyPIm1peyUgQ -LErdRTAJBgNVHRMEAjAAMAsGA1UdDwQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcD -ATAdBgNVHQ4EFgQU7XO2i2IykvfcecBTdKGUA8zYxAUwDQYJKoZIhvcNAQELBQAD -ggEBACCt6e3OSOVhqf/hD4rOJMi8rTlOMBroI8ErbDuXKF3NBNfe3vIZBtqaDxeC -1XhuSFAH5RYJupRF/vRlW58M+r1qeRakhHIpFEJDJle0dr3kw27IS+OyxSH4d3vd -3PvUsPLAtO8Cz/SXo6OkkEboNwEWmCuOWjyyj2lbDVpO3wPVUcy7kRLQBqGnv+Eu -xY059qByIZqr0SKrn0MttCRZbfzngdVXyQjC9wyTrQ+yDCE0Cng5omvw7pFrUb/W -0v/JJYXrXXM7/JEtxC2+kbp3uH8zcDorOS3pVtHRROhHSvi83ggTHFCEXzUVtWNH -M7aWXTM62DaugxDtvaPkfyS4Bv8= +MIIDSTCCAjGgAwIBAgIUFoZzGii77TrKqg6r5NgmrqGNb8UwDQYJKoZIhvcNAQEL +BQAwEjEQMA4GA1UEAwwHaGRfcm9vdDAeFw0yNjAxMzExMjA3MzlaFw0yNzAxMzEx +MjA3MzlaMA4xDDAKBgNVBAMMA2xhbjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC +AQoCggEBAJmkEtAdsqVR8zVVoGgVL351Z5spsDbkjYGqM83XN6Edkx33c64FuoOY +MpD/NqoC7eReQGJ3Oz6cjF+Oe35gO1jyJsQmsjCFVyzyihDjtczGAE6SoaS67kaq +w2K54myAGo2ESKkzU776gZM0/V44tJuJVWBumxWHmajSgsAdBCGIUKSJJolJvt90 +ghyuoTLS9u1B2wtNvhvWHEwpzCOV3LwWraroDHYXL2tKTMrpqpj6lev/8t9gIPCM +/q2oN0ILSPyScpuQHP0/Aky9kPycw3EdiTNPqh2UnI/2pw0LNHa3F3dp/f47kqSd +DlXLkveKPgJLRIbxCJGdgvoacGMce0MCAwEAAaOBmjCBlzAoBgNVHREEITAfgghy +b2FtLmxhboIKKi5yb2FtLmxhboIHZ2l0LmxhbjAfBgNVHSMEGDAWgBRkr8YAWbZl +BTwJQhL2gAyzEk/dhTAJBgNVHRMEAjAAMAsGA1UdDwQEAwIFoDATBgNVHSUEDDAK +BggrBgEFBQcDATAdBgNVHQ4EFgQUNLp+qukOiO3z/cfjk4fBalMnOswwDQYJKoZI +hvcNAQELBQADggEBAFoDA+AHIdBUtpTa1bVXSy4Y53Kn2OMopA47qxY+sgXS0UGx +2fz7dyhy68AG3V5VnVKpnNAjJdeZdQww3N7KNmjsoI+p5mS+AHucLcMLJaqFaA0t ++jyLepQFdeh2/VkmbIwFQW+T/oBoCP4i4tkmaa/9mKSkbEOAadcucg7viqmRKN/b +DJNMkhiahpCATpxRno8ybUzn907UTKBQOseZMW53ecKkgcPQOF6apsM7+/jXkOrO +D9QeVWCdLLAnpLlubqbuGxPjI0RbLHXwKFayRwKEMj3Gn9njqcZfkVM3QJHc8Pn9 +eADOacl+F1jPO2nTTOQ9tZzfyHW4Gd5tpWqpEb8= -----END CERTIFICATE----- diff --git a/secrets/tlskey.age b/secrets/tlskey.age index 99fc887b4d35cfff12996232836182b3cbb190f8..6e17a6718e8c352898f7fec7f081c80e61da073a 100644 GIT binary patch delta 2187 zcmX>mcua7DPJNhpcvQHHS5S7YTcv?xkYm1^sfAggv8QXXVOfZGc}cN(iCdPleo<9U zD3_~AT3(57agwK#xuIi4RAHb?Xil=ZTa{~-eo}=?lDUgZm3EPfuUn2`B$uw8LUD11 zZfc5=si~o*f@hMeWtF3Xwsw|dva`QaS*Bx7wpU27lUqTdVM(T!mybngMrgTnRgi&E zL9uaIVN#GMSAcf9sgt2esk2X&cT|;2MM0ReQBh@CvR9O!Utw}kVP>FrsYyh7W=>V| z#E;_PC843=ZZ1*zRY?)PKBnnLso4>E8Ahd{u8D?jW*HI2`i51R{w0-u*}=YCM*g`) zeui#l0il-Ro&m*%K2-*V-XXyjX~F5!z~j{Lron`JPnGH3sfO)bib%mWi$JgN)|GfRz} zO>+whj8h6yBg}%r+{^Rovw{suGQ)H8xytRte6}&Z_v(7D{@>aD;eSK@rE6V<-qd=W zce|~oE8Ko<)lmW4@MF%~b$2rb@&0SBJD8PZB{Ol)*9#{$GGwS0xZh4RV)^alT4Pr0 z@<%&dyueJK<;c;{cNvC^FPZJ-<1DMxMO^xv=8D^W4ey?yW6dA9sxUVU{ zN#mtAT)zbi%H~YSej0gow{AjHvEQ~k_4Ou>dp+A(^rCd{McOx9it%O6J#g4AbPiM9 zhr0K=7W03eopt8mnq_>|^i}QuA@i42BRpEB z|C>xmY;evuYcJqZ!MVrf8zhrpo4Y1(f3}@&A+cy^AAg=PFu7`w zc4sf!QVrqr(_T+pap+QMBLD4O-DVqVv=e79x}hw$MMsP$;bi3tOWo<*rpGTbK69;E zzscnZ-}O9J z8C${^dOJL8Q^f}T;QD6e3tP3mEfk(zu(l_Ap}WG>V<)!lJGAcHHG3w-%aWld>Z_0Ja9rQJ zOmzuBJrgZC6;`Q}Y!Z)JA*KkGzuy%guU8%G+WS>hD$xLk6MWQCkZ@% zvds7Lo{8#zbJD(r=ec#-&nsQl&CHv;`{*esQJKS?X{kj!n-cj;gKH_6{>m0o1e-WY3pU$!w< z`y=~j@8j###fx|CIKY45Yu7`zkM9c@->#T_sxos5?^3192Q))(lyIp|UibL??`=1d zRZnhct<>G<+W`o?B~fahB+CNu4+m(r1wQdcH*V&z;|V zx`louPkq%MXZc9&SiLFd=cCP{i)TB^FS{~H-v07WmlmB9mO@+knL9!jS9?A=xb1A& z?WAqx?-mHKl{IuYUA*#(jhk8ZklgjitsASqw^i>oPvBAie|5?$_TRF1MYHwi$woS| z%=g+5@Y-nt`z2$mVB=fdOICXvXt$YBFJbL|`c1GN$0Z+!i9hWxty#aVK8NAI`NF%B zd+Uy0Iyia8nuf^fl67JI7xvE9mWtzuOR?KEDT(*1;_0MWb6$tklz8tf>EZrc5VA5f zSk>*|_7_6$u3dhT^n&jp|4PsIza9t6rv%;4-L}YQ>(xWo=Y8-r67*x3uzU9c)_b~} zoO{CFUTpVRIBUKL=c3(FbMEXDOgBrf-|4kuZmOKrm+VmfnW7S_&ADf_hMYUGP-M6U2 zW&U)NNpW#$A)mcua7DPJL-1Iil<&H(ZApwEKDS5?Qenx&l z>1Gk-9w8zAi6)+T87V<&IXPh!?w-jZg%MR=mSL41>8}1sNyP?};~B;4&3yySeceJ# zGA%1D{6Y;w10za&J)A33^9-{y{k)5l!i-(hbBeRd94qpB|yT*5l ztIsZ_g1P@Cg7nYt*sgi!os-yqsqK5V#y7Bg9gBJCm@!xTeBs@bJ9;Obz2{t?+LG`3 zZIYVCe!bPN`WCQ6pALIJ>+e3Vc9+2aGu7Amgm;_i#Qa%sLU-#)ohL;RcjoBbUG3f9 zwN*R4#*iuEpy~ZirpZnJFSWWYni24A>us6xlI4Xw=BbQ_t*@?oG56t7sV8CC@}KlV z^;8&of_HQ6OibB7DfMIhp?gN>Qh&3bSzE7Fk;&sF8)C%7wB*~>pCOXUN_i!zemQ&B zH9DS=c8mC+wS1bkhxp4HjaB;??6@RXIvTut^<|D+w`qxis`u07#T7|BJdCwDOaB;6 zly6=fRG3(?&fxw+F}rOosxwMT{%4iSUE83=x&7(;i%H@O1D^z}*Zj`NH|eHW$GQ1= zk{^ug51;yU{o(!jPVCQhN@GKISpA#gH2Iv$ox@73y#*`f-!p1=U0Qzk!)@pF?@X6k zeUA6pV$&e(QL=hQGDGv`KODxdTK-I$!pgwuxsy$3*=^?iEH_Kva=vd9y|Uo2$)ZDB z-6CIg7A%|L;~8$z=gqcs{-iDU91a#L{yDm2=Wc_irxSPAzgx2W(Q}rA+5YpsZcCnb z{Ir~Vl&pDNiMpVIDAU!8)t!QR+e81T%$fJ#Xa0r^w=32Q+<&ob__Ung_M!XC;*ad> z+qd}a%Uodoa+~QCvz4BIl>RP!-paVq=z_mma`_gcw@WLpPg=g}=}}$tt*7sM=~$Xx zfblj7z5`#wo?#!Jr`Z!TpT%6E;4lo;e%( zDZXM@evPNx!YFu+;CsQIjT?N|TwbNLkKI=2@B2*Chiqk8?cV}c@%23UERuB4U`8dY z$8m#X`KfI7#_=zMq}LTboL2klLRhKny;Cz&Zr*&L){rT3ZM}4Gtx+LMaQ&y`tqR!qv= zIkT-c^wO<`#@rJQs=N}N7`s?BN43M`e98V?|Ec{Nt39{v_L!Ns={4uRBUSTElCHJv zGs*m+;qkq8^ZnYOGp0{lclw-o89!;KX#Lg?&-U#7x#H4tL6;W+zZ748m@0cX1gh|J%j81Q+a?|6qw?qw5>l|2gUWwyP)m{rS9ihLir} zfRj(+3+o?#k*;2FIk9z1$BMdhEi&_(%TEMdR(4tXK9AvIOt8-sm%#sPw#(c&wd~7l z`|ZhU_c(5>dUPSS=>4^19tESP=Jkm#}_>YUum_^)UwVZX2(zkdh7L{46Z6 z$I`UyO!upMY<==Nnn#v)@J#-C*Dp4hp())|X`$>>ri0tI-Sih%IOkz?cgE{C>r(Vj zt^Bw+_^X2VvyV~+4%5@$-kGy$<>4b6Z;5`_+-Tds{lW$lMLkbV-?Pe+f3;X{uQFR| zsNNCba$!Q-@5vi2Q*QjJe^b764|}10VLIdUMW5%I{gV22puEmV`ghl{fI3^X4d*65 z2uQe~CiYML>(?WvU6kb*dkhp~-d4`JmmB~7&!OZ`N14yvYjd;D+Tv=}w)(a3FY7ql z&&L*AIq`XuhLzs6r&gJr_tQ>WmZT^hTYlSZ%kSAo|3AE&W3N34Bfoq znS;;XD;4k8{@pP%C-=n?x$tLRe5|FO^E!SWmVYKc-F?O>p%d1fqU)9lo%1>JRsYk{ z-%9U4$*whxoA&)q`K_W3s{;Z>a^Z4q@^YsSE-F`z+dsqHFu7|j&r7+cn;t$tZCn;A zH0}Jhg)44>%@%`Sk8?DVzR%`)?!WE-!ryyOc${4Nt>~%y{NV3)D_$mK>K26xece6j z$wa9K=J%fb2>$Ol?``FLt`#1-EeG2c#GgECW4wRj{pDIp%w3VmKeM^a9Dc