netscaler.adc.sslcrl module – Configuration for Certificate Revocation List resource.
Note
This module is part of the netscaler.adc collection (version 2.6.2).
It is not included in ansible-core
.
To check whether it is installed, run ansible-galaxy collection list
.
To install it, use: ansible-galaxy collection install netscaler.adc
.
To use it in a playbook, specify: netscaler.adc.sslcrl
.
New in netscaler.adc 2.0.0
Synopsis
Configuration for Certificate Revocation List resource.
Parameters
Parameter |
Comments |
---|---|
Base NITRO API path. Define only in case of an ADM service proxy call Default: |
|
Base distinguished name (DN), which is used in an LDAP search to search for a CRL. Citrix recommends searching for the Base DN instead of the Issuer Name from the CA certificate, because the Issuer Name field might not exactly match the LDAP directory structure’s DN. |
|
Set the LDAP-based CRL retrieval mode to binary. Choices:
|
|
Bind distinguished name (DN) to be used to access the CRL object in the LDAP repository if access to the LDAP repository is restricted or anonymous access is not allowed. |
|
CA certificate that has issued the CRL. Required if CRL Auto Refresh is selected. Install the CA certificate on the appliance before adding the CRL. |
|
Name of and, optionally, path to the CA certificate file. /nsconfig/ssl/ is the default path. |
|
Name of and, optionally, path to the CA key file. /nsconfig/ssl/ is the default path |
|
Name for the Certificate Revocation List (CRL). Must begin with an ASCII alphanumeric or underscore (_) character, and must contain only ASCII alphanumeric, underscore, hash (#), period (.), space, colon (:), at (@), equals (=), and hyphen (-) characters. Cannot be changed after the CRL is created. The following requirement applies only to the Citrix ADC CLI: If the name includes one or more spaces, enclose the name in double or single quotation marks (for example, “my crl” or ‘my crl’). |
|
Path to the CRL file. /var/netscaler/ssl/ is the default path. |
|
Day on which to refresh the CRL, or, if the Interval parameter is not set, the number of days after which to refresh the CRL. If Interval is set to MONTHLY, specify the date. If Interval is set to WEEKLY, specify the day of the week (for example, Sun=0 and Sat=6). This parameter is not applicable if the Interval is set to DAILY. |
|
Name of and, optionally, path to the CRL file to be generated. The list of certificates that have been revoked is obtained from the index file. /nsconfig/ssl/ is the default path. |
|
Name of and, optionally, path to the file containing the serial numbers of all the certificates that are revoked. Revoked certificates are appended to the file. /nsconfig/ssl/ is the default path |
|
Input format of the CRL file. The two formats supported on the appliance are:
Choices:
|
|
CRL refresh interval. Use the Choices:
|
|
The ID of the managed NetScaler instance to which NetScaler Console has to configure as a proxy server. Define only in case of an ADM service proxy call |
|
The IP of the managed NetScaler instance to which NetScaler Console has to configure as a proxy server. Define only in case of an ADM service proxy call |
|
The name of the managed NetScaler instance to which NetScaler Console has to configure as a proxy server. Define only in case of an ADM service proxy call |
|
The password of the managed NetScaler instance. Define only in case of an ADM service proxy call In Settings > Administration > System Configurations > Basic Settings, if you select Prompt Credentials for Instance Login, ensure to configure username and password of a managed instance. |
|
The username of the managed NetScaler instance. Define only in case of an ADM service proxy call In Settings > Administration > System Configurations > Basic Settings, if you select Prompt Credentials for Instance Login, ensure to configure username and password of a managed instance. |
|
Method for CRL refresh. If Choices:
|
|
The IP address of the NetScaler ADC appliance acting as a proxy server. Define only in case of an ADM service proxy call Choices:
|
|
The authentication token provided by a login operation. |
|
The password with which to authenticate to the NetScaler ADC node. |
|
Which protocol to use when accessing the nitro API objects. Choices:
|
|
The username with which to authenticate to the NetScaler ADC node. |
|
The ip address of the NetScaler ADC appliance where the nitro API calls will be made. The port can be specified with the colon (:). E.g. 192.168.1.1:555. |
|
Password to access the CRL in the LDAP repository if access to the LDAP repository is restricted or anonymous access is not allowed. |
|
Port for the LDAP server. |
|
Set CRL auto refresh. Choices:
|
|
Name of and, optionally, path to the certificate to be revoked. /nsconfig/ssl/ is the default path. |
|
If The module will not save the configuration on the NetScaler ADC node if it made no changes. Choices:
|
|
Extent of the search operation on the LDAP server. Available settings function as follows:
Choices:
|
|
IP address of the LDAP server from which to fetch the CRLs. |
|
The state of the resource being configured by the module on the NetScaler ADC node. When When When When Choices:
|
|
Time, in hours (1-24) and minutes (1-60), at which to refresh the CRL. |
|
URL of the CRL distribution point. |
|
If Choices:
|
Notes
Note
For more information on using Ansible to manage NetScaler ADC Network devices see https://www.ansible.com/integrations/networks/citrixadc.
Examples
---
- name: Sample sslcrl playbook
hosts: demo_netscalers
gather_facts: false
tasks:
- name: Configure sslcrl
delegate_to: localhost
netscaler.adc.sslcrl:
state: present
crlname: crl_test_ldap1
refresh: ENABLED
cacert: ssl_cacert
server: 2.2.2.10
method: LDAP
port: 389
basedn: cn=ldap_new_crl_pem,ou=dsd,o=ns,c=in
scope: Base
day: '23'
time: 00:01
binddn: cn=Manager,dc=netscaler,dc=com
password: free
binary: 'YES'
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
---|---|
Indicates if any change is made by the module Returned: always Sample: |
|
Dictionary of before and after changes Returned: always Sample: |
|
List of differences between the actual configured object and the configuration specified in the module Returned: when changed Sample: |
|
Indicates if the module failed or not Returned: always Sample: |
|
list of logged messages by the module Returned: always Sample: |