Rework glance config file for X.509 RMQ Auth

Change-Id: I80f7be8782876f20b40f8faa3acd6ca2f0e1de6c
diff --git a/glance/files/pike/glance-api.conf.Debian b/glance/files/pike/glance-api.conf.Debian
index 248c648..0bcab9b 100644
--- a/glance/files/pike/glance-api.conf.Debian
+++ b/glance/files/pike/glance-api.conf.Debian
@@ -3683,18 +3683,18 @@
 {%- if server.message_queue.get('ssl',{}).get('enabled', False) %}
 rabbit_use_ssl=true
 
-{%- if server.message_queue.ssl.version is defined %}
+  {%- if server.message_queue.ssl.version is defined %}
 kombu_ssl_version = {{ server.message_queue.ssl.version }}
-{%- elif salt['grains.get']('pythonversion') > [2,7,8] %}
+  {%- elif salt['grains.get']('pythonversion') > [2,7,8] %}
 kombu_ssl_version = TLSv1_2
-{%- endif %}
+  {%- endif %}
 
-kombu_ssl_ca_certs = {{ server.message_queue.ssl.get('cacert_file', server.cacert_file) }}
 {%- if server.message_queue.get('x509',{}).get('enabled', False) %}
-
-kombu_ssl_keyfile = {{ server.message_queue.x509.key_file}}
-
-kombu_ssl_certfile = {{ server.message_queue.x509.cert_file}}
+kombu_ssl_ca_certs = {{ server.message_queue.x509.ca_file }}
+kombu_ssl_keyfile = {{ server.message_queue.x509.key_file }}
+kombu_ssl_certfile = {{ server.message_queue.x509.cert_file }}
+{%- else %}
+kombu_ssl_ca_certs = {{ server.message_queue.ssl.get('cacert_file', server.cacert_file) }}
 {%- endif %}
 
 {%- endif %}
diff --git a/glance/files/pike/glance-registry.conf.Debian b/glance/files/pike/glance-registry.conf.Debian
index 6589a46..e6553d7 100644
--- a/glance/files/pike/glance-registry.conf.Debian
+++ b/glance/files/pike/glance-registry.conf.Debian
@@ -1582,19 +1582,19 @@
 {%- if server.message_queue.get('ssl',{}).get('enabled', False) %}
 rabbit_use_ssl=true
 
-{%- if server.message_queue.ssl.version is defined %}
+  {%- if server.message_queue.ssl.version is defined %}
 kombu_ssl_version = {{ server.message_queue.ssl.version }}
-{%- elif salt['grains.get']('pythonversion') > [2,7,8] %}
+  {%- elif salt['grains.get']('pythonversion') > [2,7,8] %}
 kombu_ssl_version = TLSv1_2
-{%- endif %}
+  {%- endif %}
 
-kombu_ssl_ca_certs = {{ server.message_queue.ssl.get('cacert_file', server.cacert_file) }}
-{%- if server.message_queue.get('x509',{}).get('enabled', False) %}
-
+  {%- if server.message_queue.get('x509',{}).get('enabled', False) %}
+kombu_ssl_ca_certs = {{ server.message_queue.x509.ca_file }}
 kombu_ssl_keyfile = {{ server.message_queue.x509.key_file}}
-
 kombu_ssl_certfile = {{ server.message_queue.x509.cert_file}}
-{%- endif %}
+  {%- else %}
+kombu_ssl_ca_certs = {{ server.message_queue.ssl.get('cacert_file', server.cacert_file) }}
+  {%- endif %}
 
 {%- endif %}