integrate dnsdist in session ticket keys management

This commit is contained in:
Daniel Micay 2025-05-27 14:46:25 -04:00
parent 6555042a88
commit 57a5209d8b
3 changed files with 9 additions and 4 deletions

View file

@ -1,6 +1,6 @@
[Unit]
Description=Create TLS session ticket keys
Before=nginx.service
Before=dnsdist.service nginx.service
[Service]
ExecStart=/usr/local/bin/create-session-ticket-keys

View file

@ -1,7 +1,7 @@
[Unit]
Description=Rotate TLS session ticket keys
After=nginx.service create-session-ticket-keys.service
Requires=nginx.service create-session-ticket-keys.service
After=dnsdist.service nginx.service create-session-ticket-keys.service
Requires=create-session-ticket-keys.service
[Service]
ExecStart=/usr/local/bin/rotate-session-ticket-keys

View file

@ -13,4 +13,9 @@ rm new.key
cat {1..4}.key > keys.new
rsync -I keys.new keys
rm keys.new
nginx -s reload
if systemctl is-enabled nginx.service >/dev/null; then
nginx -s reload
fi
if systemctl is-enabled dnsdist.service >/dev/null; then
dnsdist -c -e 'reloadAllCertificates()'
fi