paloaltonetworks.panos.panos_cert_gen_ssh module – generates a self-signed certificate using SSH protocol with SSH key

Note

This module is part of the paloaltonetworks.panos collection (version 2.21.2).

To install it, use: ansible-galaxy collection install paloaltonetworks.panos. You need further requirements to be able to use this module, see Requirements for details.

To use it in a playbook, specify: paloaltonetworks.panos.panos_cert_gen_ssh.

New in paloaltonetworks.panos 1.0.0

Synopsis

  • This module generates a self-signed certificate that can be used by GlobalProtect client, SSL connector, or

  • otherwise. Root certificate must be preset on the system first. This module depends on paramiko for ssh.

Requirements

The below requirements are needed on the host that executes this module.

  • paramiko

Parameters

Parameter

Comments

cert_cn

string / required

Certificate CN (common name) embedded in the certificate signature.

cert_friendly_name

string / required

Human friendly certificate name (not CN but just a friendly name).

ip_address

string / required

IP address (or hostname) of PAN-OS device being configured.

key_filename

string

Location of the filename that is used for the auth. Either key_filename or password is required.

password

string

Password credentials to use for auth. Either key_filename or password is required.

rsa_nbits

string

Number of bits used by the RSA algorithm for the certificate generation.

Default: :ansible-option-default:`"2048"`

signed_by

string / required

Undersigning authority (CA) that MUST already be presents on the device.

username

string

User name to use for auth. Default is admin.

Default: :ansible-option-default:`"admin"`

Notes

Note

  • Checkmode is not supported.

Examples

# Generates a new self-signed certificate using ssh
- name: generate self signed certificate
  paloaltonetworks.panos.panos_cert_gen_ssh:
    ip_address: "192.168.1.1"
    username: "admin"
    password: "paloalto"
    cert_cn: "1.1.1.1"
    cert_friendly_name: "test123"
    signed_by: "root-ca"

Authors

  • Luigi Mori (@jtschichold), Ivan Bojer (@ivanbojer)