Add changelog fragments from ansible/ansible. (#8)

pull/25/head
Felix Fontein 2020-03-31 16:12:58 +02:00 committed by GitHub
parent 88ee99423c
commit bffd7b0ce9
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
25 changed files with 69 additions and 0 deletions

View File

@ -0,0 +1,2 @@
minor_changes:
- luks_device - accept ``passphrase``, ``new_passphrase`` and ``remove_passphrase``.

View File

@ -0,0 +1,2 @@
minor_changes:
- luks_device - added the ``type`` option that allows user explicit define the LUKS container format version

View File

@ -0,0 +1,2 @@
minor_changes:
- luks_device - added support to use UUIDs, and labels with LUKS2 containers

View File

@ -0,0 +1,2 @@
minor_changes:
- "openssl_privatekey - add ``format`` and ``format_mismatch`` options."

View File

@ -0,0 +1,2 @@
minor_changes:
- luks_device - add ``keysize`` parameter to set key size at LUKS container creation

View File

@ -0,0 +1,2 @@
bugfixes:
- "openssh_keypair - public key's file attributes (permissions, owner, group, etc.) are now set to the same values as the private key."

View File

@ -0,0 +1,2 @@
bugfixes:
- ecs_certificate - Fix formatting of contents of ``full_chain_path``.

View File

@ -0,0 +1,3 @@
bugfixes:
- "openssl_certificate - When provider is ``entrust``, use a ``connection: keep-alive`` header for ECS API connections."
- "ecs_certificate - Always specify header ``connection: keep-alive`` for ECS API connections."

View File

@ -0,0 +1,2 @@
bugfixes:
- "openssl_certificate - fix ``assertonly`` provider certificate verification, causing 'private key mismatch' and 'subject mismatch' errors."

View File

@ -0,0 +1,2 @@
minor_changes:
- "openssl_dhparam - now supports a ``cryptography``-based backend. Auto-detection can be overwritten with the ``select_crypto_backend`` option."

View File

@ -0,0 +1,4 @@
deprecated_features:
- "openssl_csr - all values for the ``version`` option except ``1`` are deprecated."
bugfixes:
- "openssl_csr - a warning is issued if an unsupported value for ``version`` is used for the ``cryptography`` backend."

View File

@ -0,0 +1,4 @@
bugfixes:
- "openssl_certificate and openssl_csr - fix Ed25519 and Ed448 private key support for ``cryptography`` backend.
This probably needs at least cryptography 2.8, since older versions have problems with signing certificates
or CSRs with such keys. (https://github.com/ansible/ansible/issues/59039, PR https://github.com/ansible/ansible/pull/63984)"

View File

@ -0,0 +1,4 @@
bugfixes:
- openssh_keypair - add logic to avoid breaking password protected keys.
minor_changes:
- openssh_keypair - instead of regenerating some broken or password protected keys, fail the module. Keys can still be regenerated by calling the module with ``force=yes``.

View File

@ -0,0 +1,2 @@
bugfixes:
- "acme_certificate - fix crash when module is used with Python 2.x."

View File

@ -0,0 +1,2 @@
bugfixes:
- "acme_certificate - fix misbehavior when ACME v1 is used with ``modify_account`` set to ``false``."

View File

@ -0,0 +1,2 @@
bugfixes:
- "openssh_keypair - fixes idempotence issue with public key (https://github.com/ansible/ansible/issues/64969)."

View File

@ -0,0 +1,7 @@
minor_changes:
- "openssl_certificate - allow to return the existing/generated certificate directly as ``certificate`` by setting ``return_content`` to ``yes``."
- "openssl_csr - allow to return the existing/generated CSR directly as ``csr`` by setting ``return_content`` to ``yes``."
- "openssl_dhparam - allow to return the existing/generated DH params directly as ``dhparams`` by setting ``return_content`` to ``yes``."
- "openssl_pkcs12 - allow to return the existing/generated PKCS#12 directly as ``pkcs12`` by setting ``return_content`` to ``yes``."
- "openssl_privatekey - allow to return the existing/generated private key directly as ``privatekey`` by setting ``return_content`` to ``yes``."
- "openssl_publickey - allow to return the existing/generated public key directly as ``publickey`` by setting ``return_content`` to ``yes``."

View File

@ -0,0 +1,2 @@
bugfixes:
- "openssl_csr - the module will now enforce that ``privatekey_path`` is specified when ``state=present``."

View File

@ -0,0 +1,2 @@
bugfixes:
- "openssl_certificate - ``provider`` option was documented as required, but it was not checked whether it was provided. It is now only required when ``state`` is ``present``."

View File

@ -0,0 +1,7 @@
minor_changes:
- "openssl_certificate_info - allow to provide certificate content via ``content`` option (https://github.com/ansible/ansible/issues/64776)."
- "openssl_csr_info - allow to provide CSR content via ``content`` option."
- "openssl_privatekey_info - allow to provide private key content via ``content`` option."
- "openssl_certificate - allow to provide content of some input files via the ``csr_content``, ``privatekey_content``, ``ownca_privatekey_content`` and ``ownca_content`` options."
- "openssl_csr - allow to provide private key content via ``private_key_content`` option."
- "openssl_publickey - allow to provide private key content via ``private_key_content`` option."

View File

@ -0,0 +1,2 @@
bugfixes:
- "openssl_publickey - fix a module crash caused when pyOpenSSL is not installed (https://github.com/ansible/ansible/issues/67035)."

View File

@ -0,0 +1,3 @@
minor_changes:
- "openssh_keypair - the ``regenerate`` option allows to configure the module's behavior when it should or needs to regenerate private keys."
- "openssl_privatekey - the ``regenerate`` option allows to configure the module's behavior when it should or needs to regenerate private keys."

View File

@ -0,0 +1,3 @@
minor_changes:
- "openssl_certificate - Add option for changing which ACME directory to use with acme-tiny. Set the default ACME directory to Let's Encrypt instead of using acme-tiny's default. (acme-tiny also uses Let's Encrypt at the time being, so no action should be neccessary.)"
- "openssl_certificate - Change the required version of acme-tiny to >= 4.0.0"

View File

@ -0,0 +1,2 @@
bugfixes:
- "openssl_* modules - prevent crash on fingerprint determination in FIPS mode (https://github.com/ansible/ansible/issues/67213)."

View File

@ -0,0 +1,2 @@
bugfixes:
- get_certificate - Fix cryptography backend when pyopenssl is unavailable (https://github.com/ansible/ansible/issues/67900)