mirror of
https://github.com/GrapheneOS/infrastructure.git
synced 2025-08-02 11:36:13 -04:00
integrate dnsdist in session ticket keys management
This commit is contained in:
parent
6555042a88
commit
57a5209d8b
3 changed files with 9 additions and 4 deletions
|
@ -1,6 +1,6 @@
|
|||
[Unit]
|
||||
Description=Create TLS session ticket keys
|
||||
Before=nginx.service
|
||||
Before=dnsdist.service nginx.service
|
||||
|
||||
[Service]
|
||||
ExecStart=/usr/local/bin/create-session-ticket-keys
|
||||
|
|
|
@ -1,7 +1,7 @@
|
|||
[Unit]
|
||||
Description=Rotate TLS session ticket keys
|
||||
After=nginx.service create-session-ticket-keys.service
|
||||
Requires=nginx.service create-session-ticket-keys.service
|
||||
After=dnsdist.service nginx.service create-session-ticket-keys.service
|
||||
Requires=create-session-ticket-keys.service
|
||||
|
||||
[Service]
|
||||
ExecStart=/usr/local/bin/rotate-session-ticket-keys
|
||||
|
|
|
@ -13,4 +13,9 @@ rm new.key
|
|||
cat {1..4}.key > keys.new
|
||||
rsync -I keys.new keys
|
||||
rm keys.new
|
||||
nginx -s reload
|
||||
if systemctl is-enabled nginx.service >/dev/null; then
|
||||
nginx -s reload
|
||||
fi
|
||||
if systemctl is-enabled dnsdist.service >/dev/null; then
|
||||
dnsdist -c -e 'reloadAllCertificates()'
|
||||
fi
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue