[REFACTOR] Implement X.509 auth for MySQL and Nova
Related-PROD: PROD-19981
Change-Id: Ifee72be381c6a5bd13daff3e62f3d57319a07989
diff --git a/salt/minion/cert/mysql/clients/openstack/nova.yml b/salt/minion/cert/mysql/clients/openstack/nova.yml
index 154a553..955d6eb 100644
--- a/salt/minion/cert/mysql/clients/openstack/nova.yml
+++ b/salt/minion/cert/mysql/clients/openstack/nova.yml
@@ -2,9 +2,9 @@
_param:
salt_minion_ca_host: cfg01.${_param:cluster_domain}
salt_minion_ca_authority: salt_master_ca
- mysql_nova_client_ssl_key_file: /etc/pki/mysql-nova-client/client-key.pem
- mysql_nova_client_ssl_cert_file: /etc/pki/mysql-nova-client/client-cert.pem
- mysql_nova_ssl_ca_file: /etc/pki/mysql-nova-client/ca-cert.pem
+ mysql_nova_client_ssl_key_file: /etc/nova/ssl/mysql/client-key.pem
+ mysql_nova_client_ssl_cert_file: /etc/nova/ssl/mysql/client-cert.pem
+ mysql_nova_ssl_ca_file: /etc/nova/ssl/mysql/ca-cert.pem
salt:
minion:
cert:
@@ -24,4 +24,4 @@
ca_file: ${_param:mysql_nova_ssl_ca_file}
user: nova
group: nova
- mode: 640
\ No newline at end of file
+ mode: 640