ansible-playbook 2.9.27 config file = /etc/ansible/ansible.cfg configured module search path = [u'/root/.ansible/plugins/modules', u'/usr/share/ansible/plugins/modules'] ansible python module location = /usr/lib/python2.7/site-packages/ansible executable location = /usr/bin/ansible-playbook python version = 2.7.5 (default, Nov 14 2023, 16:14:06) [GCC 4.8.5 20150623 (Red Hat 4.8.5-44)] Using /etc/ansible/ansible.cfg as config file [WARNING]: running playbook inside collection fedora.linux_system_roles Skipping callback 'actionable', as we already have a stdout callback. Skipping callback 'counter_enabled', as we already have a stdout callback. Skipping callback 'debug', as we already have a stdout callback. Skipping callback 'dense', as we already have a stdout callback. Skipping callback 'dense', as we already have a stdout callback. Skipping callback 'full_skip', as we already have a stdout callback. Skipping callback 'json', as we already have a stdout callback. Skipping callback 'jsonl', as we already have a stdout callback. Skipping callback 'minimal', as we already have a stdout callback. Skipping callback 'null', as we already have a stdout callback. Skipping callback 'oneline', as we already have a stdout callback. Skipping callback 'selective', as we already have a stdout callback. Skipping callback 'skippy', as we already have a stdout callback. Skipping callback 'stderr', as we already have a stdout callback. Skipping callback 'unixy', as we already have a stdout callback. Skipping callback 'yaml', as we already have a stdout callback. PLAYBOOK: tests_fs_attrs.yml *************************************************** 1 plays in /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml PLAY [Ensure UID and GID exists] *********************************************** TASK [Gathering Facts] ********************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:2 Saturday 28 February 2026 07:39:16 -0500 (0:00:00.023) 0:00:00.023 ***** ok: [managed-node2] META: ran handlers TASK [Ensure user exists] ****************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:5 Saturday 28 February 2026 07:39:17 -0500 (0:00:00.974) 0:00:00.998 ***** changed: [managed-node2] => { "changed": true, "comment": "", "create_home": true, "group": 1040, "home": "/home/user1", "name": "user1", "shell": "/bin/bash", "state": "present", "system": false, "uid": 1040 } TASK [Ensure group "somegroup" exists] ***************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:11 Saturday 28 February 2026 07:39:17 -0500 (0:00:00.534) 0:00:01.533 ***** changed: [managed-node2] => { "changed": true, "gid": 1041, "name": "somegroup", "state": "present", "system": false } TASK [Issue certificate setting user/group] ************************************ task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:17 Saturday 28 February 2026 07:39:18 -0500 (0:00:00.499) 0:00:02.032 ***** TASK [fedora.linux_system_roles.certificate : Set version specific variables] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:2 Saturday 28 February 2026 07:39:18 -0500 (0:00:00.108) 0:00:02.140 ***** included: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml for managed-node2 TASK [fedora.linux_system_roles.certificate : Ensure ansible_facts used by role] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:2 Saturday 28 February 2026 07:39:18 -0500 (0:00:00.054) 0:00:02.195 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Check if system is ostree] ******* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:10 Saturday 28 February 2026 07:39:18 -0500 (0:00:00.056) 0:00:02.252 ***** ok: [managed-node2] => { "changed": false, "stat": { "exists": false } } TASK [fedora.linux_system_roles.certificate : Set flag to indicate system is ostree] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:15 Saturday 28 February 2026 07:39:18 -0500 (0:00:00.438) 0:00:02.691 ***** ok: [managed-node2] => { "ansible_facts": { "__certificate_is_ostree": false }, "changed": false } TASK [fedora.linux_system_roles.certificate : Run systemctl] ******************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:22 Saturday 28 February 2026 07:39:18 -0500 (0:00:00.054) 0:00:02.745 ***** ok: [managed-node2] => { "changed": false, "cmd": [ "systemctl", "is-system-running" ], "delta": "0:00:00.007859", "end": "2026-02-28 07:39:19.247437", "failed_when_result": false, "rc": 0, "start": "2026-02-28 07:39:19.239578" } STDOUT: running TASK [fedora.linux_system_roles.certificate : Require installed systemd] ******* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:30 Saturday 28 February 2026 07:39:19 -0500 (0:00:00.400) 0:00:03.146 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Set flag to indicate that systemd runtime operations are available] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:35 Saturday 28 February 2026 07:39:19 -0500 (0:00:00.047) 0:00:03.194 ***** ok: [managed-node2] => { "ansible_facts": { "__certificate_is_booted": true }, "changed": false } TASK [fedora.linux_system_roles.certificate : Set platform/version specific variables] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:40 Saturday 28 February 2026 07:39:19 -0500 (0:00:00.059) 0:00:03.253 ***** skipping: [managed-node2] => (item=RedHat.yml) => { "ansible_loop_var": "item", "changed": false, "item": "RedHat.yml", "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=CentOS.yml) => { "ansible_loop_var": "item", "changed": false, "item": "CentOS.yml", "skip_reason": "Conditional result was False" } ok: [managed-node2] => (item=CentOS_7.yml) => { "ansible_facts": { "__certificate_default_directory": "/etc/pki/tls", "__certificate_packages": [ "python-pyasn1", "python-cryptography", "python-dbus" ] }, "ansible_included_var_files": [ "/tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/vars/CentOS_7.yml" ], "ansible_loop_var": "item", "changed": false, "item": "CentOS_7.yml" } skipping: [managed-node2] => (item=CentOS_7.9.yml) => { "ansible_loop_var": "item", "changed": false, "item": "CentOS_7.9.yml", "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Ensure certificate role dependencies are installed] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:5 Saturday 28 February 2026 07:39:19 -0500 (0:00:00.102) 0:00:03.356 ***** ok: [managed-node2] => { "changed": false, "rc": 0, "results": [ "python2-pyasn1-0.1.9-7.el7.noarch providing python-pyasn1 is already installed", "python2-cryptography-1.7.2-2.el7.x86_64 providing python-cryptography is already installed", "dbus-python-1.1.1-9.el7.x86_64 providing python-dbus is already installed" ] } lsrpackages: python-cryptography python-dbus python-pyasn1 TASK [fedora.linux_system_roles.certificate : Ensure provider packages are installed] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:15 Saturday 28 February 2026 07:39:20 -0500 (0:00:01.181) 0:00:04.538 ***** ok: [managed-node2] => (item=certmonger) => { "__certificate_provider": "certmonger", "ansible_loop_var": "__certificate_provider", "changed": false, "rc": 0, "results": [ "certmonger-0.78.4-17.el7_9.x86_64 providing certmonger is already installed" ] } lsrpackages: certmonger TASK [fedora.linux_system_roles.certificate : Ensure pre-scripts hooks directory exists] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:25 Saturday 28 February 2026 07:39:21 -0500 (0:00:00.558) 0:00:05.096 ***** ok: [managed-node2] => (item=certmonger) => { "__certificate_provider": "certmonger", "ansible_loop_var": "__certificate_provider", "changed": false, "gid": 0, "group": "root", "mode": "0700", "owner": "root", "path": "/etc/certmonger//pre-scripts", "secontext": "unconfined_u:object_r:etc_t:s0", "size": 4096, "state": "directory", "uid": 0 } TASK [fedora.linux_system_roles.certificate : Ensure post-scripts hooks directory exists] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:49 Saturday 28 February 2026 07:39:21 -0500 (0:00:00.464) 0:00:05.561 ***** ok: [managed-node2] => (item=certmonger) => { "__certificate_provider": "certmonger", "ansible_loop_var": "__certificate_provider", "changed": false, "gid": 0, "group": "root", "mode": "0700", "owner": "root", "path": "/etc/certmonger//post-scripts", "secontext": "unconfined_u:object_r:etc_t:s0", "size": 4096, "state": "directory", "uid": 0 } TASK [fedora.linux_system_roles.certificate : Ensure provider service is running] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:76 Saturday 28 February 2026 07:39:22 -0500 (0:00:00.379) 0:00:05.940 ***** ok: [managed-node2] => (item=certmonger) => { "__certificate_provider": "certmonger", "ansible_loop_var": "__certificate_provider", "changed": false, "enabled": true, "name": "certmonger", "state": "started", "status": { "ActiveEnterTimestamp": "Sat 2026-02-28 07:39:09 EST", "ActiveEnterTimestampMonotonic": "377827221", "ActiveExitTimestampMonotonic": "0", "ActiveState": "active", "After": "network.target system.slice systemd-journald.socket syslog.target basic.target dbus.service", "AllowIsolate": "no", "AmbientCapabilities": "0", "AssertResult": "yes", "AssertTimestamp": "Sat 2026-02-28 07:39:09 EST", "AssertTimestampMonotonic": "377799286", "Before": "multi-user.target shutdown.target", "BlockIOAccounting": "no", "BlockIOWeight": "18446744073709551615", "BusName": "org.fedorahosted.certmonger", "CPUAccounting": "no", "CPUQuotaPerSecUSec": "infinity", "CPUSchedulingPolicy": "0", "CPUSchedulingPriority": "0", "CPUSchedulingResetOnFork": "no", "CPUShares": "18446744073709551615", "CanIsolate": "no", "CanReload": "no", "CanStart": "yes", "CanStop": "yes", "CapabilityBoundingSet": "18446744073709551615", "CollectMode": "inactive", "ConditionResult": "yes", "ConditionTimestamp": "Sat 2026-02-28 07:39:09 EST", "ConditionTimestampMonotonic": "377799285", "Conflicts": "shutdown.target", "ControlGroup": "/system.slice/certmonger.service", "ControlPID": "0", "DefaultDependencies": "yes", "Delegate": "no", "Description": "Certificate monitoring and PKI enrollment", "DevicePolicy": "auto", "EnvironmentFile": "/etc/sysconfig/certmonger (ignore_errors=yes)", "ExecMainCode": "0", "ExecMainExitTimestampMonotonic": "0", "ExecMainPID": "9750", "ExecMainStartTimestamp": "Sat 2026-02-28 07:39:09 EST", "ExecMainStartTimestampMonotonic": "377799793", "ExecMainStatus": "0", "ExecStart": "{ path=/usr/sbin/certmonger ; argv[]=/usr/sbin/certmonger -S -p /var/run/certmonger.pid -n $OPTS ; ignore_errors=no ; start_time=[Sat 2026-02-28 07:39:09 EST] ; stop_time=[n/a] ; pid=9750 ; code=(null) ; status=0/0 }", "FailureAction": "none", "FileDescriptorStoreMax": "0", "FragmentPath": "/usr/lib/systemd/system/certmonger.service", "GuessMainPID": "yes", "IOScheduling": "0", "Id": "certmonger.service", "IgnoreOnIsolate": "no", "IgnoreOnSnapshot": "no", "IgnoreSIGPIPE": "yes", "InactiveEnterTimestampMonotonic": "0", "InactiveExitTimestamp": "Sat 2026-02-28 07:39:09 EST", "InactiveExitTimestampMonotonic": "377799819", "JobTimeoutAction": "none", "JobTimeoutUSec": "0", "KillMode": "control-group", "KillSignal": "15", "LimitAS": "18446744073709551615", "LimitCORE": "18446744073709551615", "LimitCPU": "18446744073709551615", "LimitDATA": "18446744073709551615", "LimitFSIZE": "18446744073709551615", "LimitLOCKS": "18446744073709551615", "LimitMEMLOCK": "65536", "LimitMSGQUEUE": "819200", "LimitNICE": "0", "LimitNOFILE": "4096", "LimitNPROC": "29173", "LimitRSS": "18446744073709551615", "LimitRTPRIO": "0", "LimitRTTIME": "18446744073709551615", "LimitSIGPENDING": "29173", "LimitSTACK": "18446744073709551615", "LoadState": "loaded", "MainPID": "9750", "MemoryAccounting": "no", "MemoryCurrent": "18446744073709551615", "MemoryLimit": "18446744073709551615", "MountFlags": "0", "Names": "certmonger.service", "NeedDaemonReload": "no", "Nice": "0", "NoNewPrivileges": "no", "NonBlocking": "no", "NotifyAccess": "none", "OOMScoreAdjust": "0", "OnFailureJobMode": "replace", "PIDFile": "/var/run/certmonger.pid", "PermissionsStartOnly": "no", "PrivateDevices": "no", "PrivateNetwork": "no", "PrivateTmp": "no", "ProtectHome": "no", "ProtectSystem": "no", "RefuseManualStart": "no", "RefuseManualStop": "no", "RemainAfterExit": "no", "Requires": "basic.target system.slice", "Restart": "no", "RestartUSec": "100ms", "Result": "success", "RootDirectoryStartOnly": "no", "RuntimeDirectoryMode": "0755", "SameProcessGroup": "no", "SecureBits": "0", "SendSIGHUP": "no", "SendSIGKILL": "yes", "Slice": "system.slice", "StandardError": "inherit", "StandardInput": "null", "StandardOutput": "journal", "StartLimitAction": "none", "StartLimitBurst": "5", "StartLimitInterval": "10000000", "StartupBlockIOWeight": "18446744073709551615", "StartupCPUShares": "18446744073709551615", "StatusErrno": "0", "StopWhenUnneeded": "no", "SubState": "running", "SyslogLevelPrefix": "yes", "SyslogPriority": "30", "SystemCallErrorNumber": "0", "TTYReset": "no", "TTYVHangup": "no", "TTYVTDisallocate": "no", "TasksAccounting": "no", "TasksCurrent": "18446744073709551615", "TasksMax": "18446744073709551615", "TimeoutStartUSec": "1min 30s", "TimeoutStopUSec": "1min 30s", "TimerSlackNSec": "50000", "Transient": "no", "Type": "dbus", "UMask": "0022", "UnitFilePreset": "disabled", "UnitFileState": "enabled", "WantedBy": "multi-user.target", "WatchdogTimestamp": "Sat 2026-02-28 07:39:09 EST", "WatchdogTimestampMonotonic": "377827189", "WatchdogUSec": "0" } } TASK [fedora.linux_system_roles.certificate : Ensure certificate requests] ***** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:86 Saturday 28 February 2026 07:39:22 -0500 (0:00:00.651) 0:00:06.591 ***** changed: [managed-node2] => (item={u'owner': u'ftp', u'ca': u'self-sign', u'group': u'ftp', u'name': u'mycert_fs_attrs', u'dns': u'www.example.com'}) => { "ansible_loop_var": "item", "changed": true, "item": { "ca": "self-sign", "dns": "www.example.com", "group": "ftp", "name": "mycert_fs_attrs", "owner": "ftp" } } MSG: Certificate requested (new). File attributes updated. changed: [managed-node2] => (item={u'owner': 1040, u'ca': u'self-sign', u'group': 1041, u'name': u'certid', u'dns': u'www.example.com'}) => { "ansible_loop_var": "item", "changed": true, "item": { "ca": "self-sign", "dns": "www.example.com", "group": 1041, "name": "certid", "owner": 1040 } } MSG: Certificate requested (new). File attributes updated. TASK [fedora.linux_system_roles.certificate : Check if test mode is supported] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:138 Saturday 28 February 2026 07:39:24 -0500 (0:00:01.617) 0:00:08.209 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Slurp the contents of the files] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:143 Saturday 28 February 2026 07:39:24 -0500 (0:00:00.042) 0:00:08.252 ***** skipping: [managed-node2] => (item=[u'cert', {u'owner': u'ftp', u'ca': u'self-sign', u'group': u'ftp', u'name': u'mycert_fs_attrs', u'dns': u'www.example.com'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "cert", { "ca": "self-sign", "dns": "www.example.com", "group": "ftp", "name": "mycert_fs_attrs", "owner": "ftp" } ], "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=[u'cert', {u'owner': 1040, u'ca': u'self-sign', u'group': 1041, u'name': u'certid', u'dns': u'www.example.com'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "cert", { "ca": "self-sign", "dns": "www.example.com", "group": 1041, "name": "certid", "owner": 1040 } ], "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=[u'key', {u'owner': u'ftp', u'ca': u'self-sign', u'group': u'ftp', u'name': u'mycert_fs_attrs', u'dns': u'www.example.com'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "key", { "ca": "self-sign", "dns": "www.example.com", "group": "ftp", "name": "mycert_fs_attrs", "owner": "ftp" } ], "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=[u'key', {u'owner': 1040, u'ca': u'self-sign', u'group': 1041, u'name': u'certid', u'dns': u'www.example.com'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "key", { "ca": "self-sign", "dns": "www.example.com", "group": 1041, "name": "certid", "owner": 1040 } ], "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=[u'ca', {u'owner': u'ftp', u'ca': u'self-sign', u'group': u'ftp', u'name': u'mycert_fs_attrs', u'dns': u'www.example.com'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "ca", { "ca": "self-sign", "dns": "www.example.com", "group": "ftp", "name": "mycert_fs_attrs", "owner": "ftp" } ], "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=[u'ca', {u'owner': 1040, u'ca': u'self-sign', u'group': 1041, u'name': u'certid', u'dns': u'www.example.com'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "ca", { "ca": "self-sign", "dns": "www.example.com", "group": 1041, "name": "certid", "owner": 1040 } ], "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Reset certificate_test_certs] **** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:151 Saturday 28 February 2026 07:39:24 -0500 (0:00:00.074) 0:00:08.326 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Create return data] ************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:155 Saturday 28 February 2026 07:39:24 -0500 (0:00:00.035) 0:00:08.362 ***** skipping: [managed-node2] => (item=certid) => { "ansible_loop_var": "cert_name", "cert_name": "certid", "changed": false, "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=mycert_fs_attrs) => { "ansible_loop_var": "cert_name", "cert_name": "mycert_fs_attrs", "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Stop tracking certificates] ****** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:169 Saturday 28 February 2026 07:39:24 -0500 (0:00:00.047) 0:00:08.409 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Remove files] ******************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:174 Saturday 28 February 2026 07:39:24 -0500 (0:00:00.047) 0:00:08.456 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Verify each user/group certificate] ************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:34 Saturday 28 February 2026 07:39:24 -0500 (0:00:00.057) 0:00:08.513 ***** included: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml for managed-node2 included: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml for managed-node2 TASK [Set virtualenv_path] ***************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:5 Saturday 28 February 2026 07:39:24 -0500 (0:00:00.128) 0:00:08.642 ***** ok: [managed-node2] => { "ansible_facts": { "__virtualenv_path": "/tmp/certificate-tests-venv" }, "changed": false } TASK [Check if system is ostree] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:12 Saturday 28 February 2026 07:39:24 -0500 (0:00:00.052) 0:00:08.694 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Set flag to indicate system is ostree] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:17 Saturday 28 February 2026 07:39:24 -0500 (0:00:00.041) 0:00:08.736 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Ensure python2 is installed] ********************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:21 Saturday 28 February 2026 07:39:24 -0500 (0:00:00.037) 0:00:08.773 ***** ok: [managed-node2] => { "changed": false, "rc": 0, "results": [ "python2-cryptography-1.7.2-2.el7.x86_64 providing python2-cryptography is already installed", "python2-cryptography-1.7.2-2.el7.x86_64 providing python2-cryptography is already installed" ] } lsrpackages: python2-cryptography TASK [Ensure python3 is installed] ********************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:31 Saturday 28 February 2026 07:39:25 -0500 (0:00:00.585) 0:00:09.359 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Retrieve certificate file stats] ***************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:41 Saturday 28 February 2026 07:39:25 -0500 (0:00:00.038) 0:00:09.397 ***** ok: [managed-node2] => { "changed": false, "stat": { "atime": 1772282363.5833337, "attr_flags": "e", "attributes": [ "extents" ], "block_size": 4096, "blocks": 8, "charset": "us-ascii", "checksum": "c668452243f011e805f1073499e318a1522d51d5", "ctime": 1772282363.6273339, "dev": 51713, "device_type": 0, "executable": false, "exists": true, "gid": 50, "gr_name": "ftp", "inode": 171877, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0640", "mtime": 1772282363.5793335, "nlink": 1, "path": "/etc/pki/tls/certs/mycert_fs_attrs.crt", "pw_name": "ftp", "readable": true, "rgrp": true, "roth": false, "rusr": true, "size": 1294, "uid": 14, "version": "18446744072279692186", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false } } TASK [Verify if certificate file exists] *************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:46 Saturday 28 February 2026 07:39:25 -0500 (0:00:00.294) 0:00:09.692 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate file owner and group] ********************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:52 Saturday 28 February 2026 07:39:25 -0500 (0:00:00.041) 0:00:09.734 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate permissions] ****************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:62 Saturday 28 February 2026 07:39:25 -0500 (0:00:00.046) 0:00:09.780 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Retrieve key file stats] ************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:68 Saturday 28 February 2026 07:39:25 -0500 (0:00:00.050) 0:00:09.831 ***** ok: [managed-node2] => { "changed": false, "stat": { "atime": 1772282363.5383334, "attr_flags": "e", "attributes": [ "extents" ], "block_size": 4096, "blocks": 8, "charset": "us-ascii", "checksum": "6759d992d7a5c02798d5d7c18284706c78ed76e4", "ctime": 1772282363.6283338, "dev": 51713, "device_type": 0, "executable": false, "exists": true, "gid": 50, "gr_name": "ftp", "inode": 168506, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0640", "mtime": 1772282363.5793335, "nlink": 1, "path": "/etc/pki/tls/private/mycert_fs_attrs.key", "pw_name": "ftp", "readable": true, "rgrp": true, "roth": false, "rusr": true, "size": 1704, "uid": 14, "version": "18446744072279692173", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false } } TASK [Verify if key file exists] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:73 Saturday 28 February 2026 07:39:26 -0500 (0:00:00.356) 0:00:10.187 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify key file owner and group] ***************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:79 Saturday 28 February 2026 07:39:26 -0500 (0:00:00.062) 0:00:10.250 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Parse certificate] ******************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:89 Saturday 28 February 2026 07:39:26 -0500 (0:00:00.079) 0:00:10.329 ***** ok: [managed-node2] => { "certificate": { "extensions": { "authorityKeyIdentifier": { "critical": false, "value": "FA:7E:99:07:A4:1A:65:64:0E:63:10:7F:64:25:F2:23:87:5C:62:50" }, "basicConstraints": { "critical": true, "value": { "ca": false } }, "extendedKeyUsage": { "critical": false, "value": [ { "name": "id-kp-serverAuth", "oid": "1.3.6.1.5.5.7.3.1" }, { "name": "id-kp-clientAuth", "oid": "1.3.6.1.5.5.7.3.2" } ] }, "keyUsage": { "critical": false, "value": [ "key_encipherment", "digital_signature" ] }, "subjectAltName": { "critical": false, "value": [ { "name": "DNS", "value": "www.example.com" } ] }, "subjectKeyIdentifier": { "critical": false, "value": "1F:77:BE:32:93:3D:D5:23:59:3A:52:72:EE:F5:EB:24:5B:5C:4E:3D" } }, "key_size": 2048, "signature_algorithm": { "algorithm": "sha256WithRSAEncryption", "signature": "8B:0F:88:69:DE:A2:C6:B3:14:EB:AA:A5:9E:99:3B:2F:50:29:7F:42:7A:D6:5B:33:60:1A:DF:06:BC:5F:71:F2:F7:ED:4B:A8:7B:E9:5F:99:CE:73:03:0E:EA:61:CD:9C:63:F6:C4:FD:EE:B8:EF:BF:02:BF:61:25:E9:32:8F:09:A4:A8:32:A8:64:CB:A8:D9:EC:2D:AE:A2:1A:BC:6E:21:24:B8:F5:7D:4E:4D:DF:AE:EB:80:80:10:13:49:34:86:70:C2:55:55:1E:66:28:EB:AA:DA:DE:0A:7D:D3:D3:73:2E:35:D6:58:2A:6B:B7:8D:B0:BB:5E:D9:F3:F8:2B:41:D1:0C:EB:A6:A0:76:04:CA:87:7D:B6:70:B8:5F:CB:AE:34:26:53:B5:86:75:3E:59:06:43:5E:A2:21:C6:24:62:03:A0:31:FC:F7:35:7E:BE:EC:43:F7:5E:A3:71:BD:B4:44:27:32:1A:E6:77:7E:D5:8A:E1:AD:55:D3:BD:DF:5F:D3:CF:E5:C1:73:D0:12:1C:11:C3:CC:D1:D9:6C:0A:A7:7E:5A:8C:EA:F7:ED:F9:E3:02:A3:50:7F:E4:CE:FD:3A:00:7A:90:59:73:A8:4D:02:C8:F1:EF:3D:76:C3:51:96:13:5D:8A:6E:7D:81:8E:53:4E:67:DD:04:2E:B2:24:38" }, "subject": [ { "name": "commonName", "oid": "2.5.4.3", "value": "www.example.com" } ], "validity": { "not_valid_after": "20270228123909Z", "not_valid_before": "20260228123923Z" } }, "changed": false } TASK [Load certificate YAML to cert_issued variable] *************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:95 Saturday 28 February 2026 07:39:27 -0500 (0:00:00.588) 0:00:10.918 ***** ok: [managed-node2] => { "ansible_facts": { "cert_issued": { "extensions": { "authorityKeyIdentifier": { "critical": false, "value": "FA:7E:99:07:A4:1A:65:64:0E:63:10:7F:64:25:F2:23:87:5C:62:50" }, "basicConstraints": { "critical": true, "value": { "ca": false } }, "extendedKeyUsage": { "critical": false, "value": [ { "name": "id-kp-serverAuth", "oid": "1.3.6.1.5.5.7.3.1" }, { "name": "id-kp-clientAuth", "oid": "1.3.6.1.5.5.7.3.2" } ] }, "keyUsage": { "critical": false, "value": [ "key_encipherment", "digital_signature" ] }, "subjectAltName": { "critical": false, "value": [ { "name": "DNS", "value": "www.example.com" } ] }, "subjectKeyIdentifier": { "critical": false, "value": "1F:77:BE:32:93:3D:D5:23:59:3A:52:72:EE:F5:EB:24:5B:5C:4E:3D" } }, "key_size": 2048, "signature_algorithm": { "algorithm": "sha256WithRSAEncryption", "signature": "8B:0F:88:69:DE:A2:C6:B3:14:EB:AA:A5:9E:99:3B:2F:50:29:7F:42:7A:D6:5B:33:60:1A:DF:06:BC:5F:71:F2:F7:ED:4B:A8:7B:E9:5F:99:CE:73:03:0E:EA:61:CD:9C:63:F6:C4:FD:EE:B8:EF:BF:02:BF:61:25:E9:32:8F:09:A4:A8:32:A8:64:CB:A8:D9:EC:2D:AE:A2:1A:BC:6E:21:24:B8:F5:7D:4E:4D:DF:AE:EB:80:80:10:13:49:34:86:70:C2:55:55:1E:66:28:EB:AA:DA:DE:0A:7D:D3:D3:73:2E:35:D6:58:2A:6B:B7:8D:B0:BB:5E:D9:F3:F8:2B:41:D1:0C:EB:A6:A0:76:04:CA:87:7D:B6:70:B8:5F:CB:AE:34:26:53:B5:86:75:3E:59:06:43:5E:A2:21:C6:24:62:03:A0:31:FC:F7:35:7E:BE:EC:43:F7:5E:A3:71:BD:B4:44:27:32:1A:E6:77:7E:D5:8A:E1:AD:55:D3:BD:DF:5F:D3:CF:E5:C1:73:D0:12:1C:11:C3:CC:D1:D9:6C:0A:A7:7E:5A:8C:EA:F7:ED:F9:E3:02:A3:50:7F:E4:CE:FD:3A:00:7A:90:59:73:A8:4D:02:C8:F1:EF:3D:76:C3:51:96:13:5D:8A:6E:7D:81:8E:53:4E:67:DD:04:2E:B2:24:38" }, "subject": [ { "name": "commonName", "oid": "2.5.4.3", "value": "www.example.com" } ], "validity": { "not_valid_after": "20270228123909Z", "not_valid_before": "20260228123923Z" } } }, "changed": false } TASK [Verify certificate subject] ********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:99 Saturday 28 February 2026 07:39:27 -0500 (0:00:00.058) 0:00:10.977 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate SAN] ************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:107 Saturday 28 February 2026 07:39:27 -0500 (0:00:00.053) 0:00:11.030 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify key size] ********************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:115 Saturday 28 February 2026 07:39:27 -0500 (0:00:00.055) 0:00:11.086 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate Key Usage] ******************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:122 Saturday 28 February 2026 07:39:27 -0500 (0:00:00.048) 0:00:11.134 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate Extended Key Usage] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:133 Saturday 28 February 2026 07:39:27 -0500 (0:00:00.047) 0:00:11.181 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Retrieve auto-renew flag] ************************************************ task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:146 Saturday 28 February 2026 07:39:27 -0500 (0:00:00.051) 0:00:11.233 ***** ok: [managed-node2] => { "changed": false, "cmd": "set -euo pipefail; getcert list -f /etc/pki/tls/certs/mycert_fs_attrs.crt | grep 'auto-renew' | sed 's/^\\s\\+auto-renew: //g'", "delta": "0:00:00.039628", "end": "2026-02-28 07:39:27.652133", "rc": 0, "start": "2026-02-28 07:39:27.612505" } STDOUT: yes TASK [Verify certificate auto-renew flag] ************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:155 Saturday 28 February 2026 07:39:27 -0500 (0:00:00.327) 0:00:11.560 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Stat commands file] ****************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:163 Saturday 28 February 2026 07:39:27 -0500 (0:00:00.061) 0:00:11.622 ***** ok: [managed-node2] => { "changed": false, "stat": { "exists": false } } TASK [Assert that commands file got removed] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:168 Saturday 28 February 2026 07:39:28 -0500 (0:00:00.331) 0:00:11.953 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Stat first-boot unit file] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:176 Saturday 28 February 2026 07:39:28 -0500 (0:00:00.058) 0:00:12.012 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert presence of first-boot unit] ************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:181 Saturday 28 February 2026 07:39:28 -0500 (0:00:00.049) 0:00:12.062 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert that first-boot unit is enabled] ********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:186 Saturday 28 February 2026 07:39:28 -0500 (0:00:00.048) 0:00:12.110 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Stat commands file] ****************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:193 Saturday 28 February 2026 07:39:28 -0500 (0:00:00.052) 0:00:12.163 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert that commands file exists] **************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:198 Saturday 28 February 2026 07:39:28 -0500 (0:00:00.052) 0:00:12.215 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Set virtualenv_path] ***************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:5 Saturday 28 February 2026 07:39:28 -0500 (0:00:00.049) 0:00:12.264 ***** ok: [managed-node2] => { "ansible_facts": { "__virtualenv_path": "/tmp/certificate-tests-venv" }, "changed": false } TASK [Check if system is ostree] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:12 Saturday 28 February 2026 07:39:28 -0500 (0:00:00.055) 0:00:12.319 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Set flag to indicate system is ostree] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:17 Saturday 28 February 2026 07:39:28 -0500 (0:00:00.054) 0:00:12.374 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Ensure python2 is installed] ********************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:21 Saturday 28 February 2026 07:39:28 -0500 (0:00:00.055) 0:00:12.429 ***** ok: [managed-node2] => { "changed": false, "rc": 0, "results": [ "python2-cryptography-1.7.2-2.el7.x86_64 providing python2-cryptography is already installed", "python2-cryptography-1.7.2-2.el7.x86_64 providing python2-cryptography is already installed" ] } lsrpackages: python2-cryptography TASK [Ensure python3 is installed] ********************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:31 Saturday 28 February 2026 07:39:29 -0500 (0:00:00.608) 0:00:13.038 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Retrieve certificate file stats] ***************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:41 Saturday 28 February 2026 07:39:29 -0500 (0:00:00.063) 0:00:13.102 ***** ok: [managed-node2] => { "changed": false, "stat": { "atime": 1772282364.1833355, "attr_flags": "e", "attributes": [ "extents" ], "block_size": 4096, "blocks": 8, "charset": "us-ascii", "checksum": "bd00cb3dae274e89f8b48238cfbd0b09cc63cab9", "ctime": 1772282364.298336, "dev": 51713, "device_type": 0, "executable": false, "exists": true, "gid": 1041, "gr_name": "somegroup", "inode": 172747, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0640", "mtime": 1772282364.1793356, "nlink": 1, "path": "/etc/pki/tls/certs/certid.crt", "pw_name": "user1", "readable": true, "rgrp": true, "roth": false, "rusr": true, "size": 1294, "uid": 1040, "version": "18446744072279692224", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false } } TASK [Verify if certificate file exists] *************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:46 Saturday 28 February 2026 07:39:29 -0500 (0:00:00.522) 0:00:13.624 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate file owner and group] ********************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:52 Saturday 28 February 2026 07:39:29 -0500 (0:00:00.067) 0:00:13.692 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate permissions] ****************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:62 Saturday 28 February 2026 07:39:29 -0500 (0:00:00.075) 0:00:13.767 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Retrieve key file stats] ************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:68 Saturday 28 February 2026 07:39:29 -0500 (0:00:00.068) 0:00:13.836 ***** ok: [managed-node2] => { "changed": false, "stat": { "atime": 1772282364.1403356, "attr_flags": "e", "attributes": [ "extents" ], "block_size": 4096, "blocks": 8, "charset": "us-ascii", "checksum": "38f63fa11d87c4227b34e1fd23d3c3eebc13132c", "ctime": 1772282364.299336, "dev": 51713, "device_type": 0, "executable": false, "exists": true, "gid": 1041, "gr_name": "somegroup", "inode": 172745, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0640", "mtime": 1772282364.1793356, "nlink": 1, "path": "/etc/pki/tls/private/certid.key", "pw_name": "user1", "readable": true, "rgrp": true, "roth": false, "rusr": true, "size": 1704, "uid": 1040, "version": "18446744072279692211", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false } } TASK [Verify if key file exists] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:73 Saturday 28 February 2026 07:39:30 -0500 (0:00:00.358) 0:00:14.195 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify key file owner and group] ***************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:79 Saturday 28 February 2026 07:39:30 -0500 (0:00:00.043) 0:00:14.238 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Parse certificate] ******************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:89 Saturday 28 February 2026 07:39:30 -0500 (0:00:00.053) 0:00:14.291 ***** ok: [managed-node2] => { "certificate": { "extensions": { "authorityKeyIdentifier": { "critical": false, "value": "FA:7E:99:07:A4:1A:65:64:0E:63:10:7F:64:25:F2:23:87:5C:62:50" }, "basicConstraints": { "critical": true, "value": { "ca": false } }, "extendedKeyUsage": { "critical": false, "value": [ { "name": "id-kp-serverAuth", "oid": "1.3.6.1.5.5.7.3.1" }, { "name": "id-kp-clientAuth", "oid": "1.3.6.1.5.5.7.3.2" } ] }, "keyUsage": { "critical": false, "value": [ "key_encipherment", "digital_signature" ] }, "subjectAltName": { "critical": false, "value": [ { "name": "DNS", "value": "www.example.com" } ] }, "subjectKeyIdentifier": { "critical": false, "value": "72:C7:02:BB:FB:D4:F9:01:D5:87:44:59:39:9C:78:03:CA:E8:5B:30" } }, "key_size": 2048, "signature_algorithm": { "algorithm": "sha256WithRSAEncryption", "signature": "64:A4:A5:AC:C4:04:C7:3A:B0:E1:2E:DD:A2:FB:76:0E:A9:6F:3B:61:86:F0:C5:63:04:21:00:A8:85:CC:E0:D3:CF:69:3E:D3:E7:47:FC:F1:A8:83:91:4E:52:59:5C:72:F2:EF:5E:34:41:6D:FF:1E:DE:E1:8F:FA:96:06:99:EE:42:D8:F9:C5:73:76:92:03:D8:4F:AC:86:FD:FC:02:44:B4:38:34:A1:91:96:1E:6A:C5:E9:53:B5:69:0C:09:4E:70:96:14:99:97:BD:2D:17:4A:67:A5:13:2A:F0:E9:4C:29:D9:AE:57:D6:D1:78:00:CF:E8:D9:D3:32:A7:CB:7E:5F:31:4A:0E:29:D7:B4:BA:68:8F:A5:91:DD:50:E3:09:8E:DA:56:5E:87:7B:86:75:5F:D5:FB:FC:09:CC:14:82:6C:9E:59:58:64:66:44:73:54:BD:66:15:A8:23:B1:FB:A4:09:29:A6:CD:5E:56:19:B6:B4:62:7C:2F:89:3F:BD:04:BA:36:70:0D:AC:36:99:AC:88:3A:F2:CB:05:B7:81:ED:85:DC:8A:FC:09:CC:D1:EF:AD:D5:B4:77:A0:D2:78:FA:E6:18:1D:71:D1:3B:BD:BB:14:B6:91:64:3D:69:0B:87:8E:1B:98:10:65:30:61:97:79:B9:75:22:EB:79:C8" }, "subject": [ { "name": "commonName", "oid": "2.5.4.3", "value": "www.example.com" } ], "validity": { "not_valid_after": "20270228123909Z", "not_valid_before": "20260228123924Z" } }, "changed": false } TASK [Load certificate YAML to cert_issued variable] *************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:95 Saturday 28 February 2026 07:39:30 -0500 (0:00:00.369) 0:00:14.661 ***** ok: [managed-node2] => { "ansible_facts": { "cert_issued": { "extensions": { "authorityKeyIdentifier": { "critical": false, "value": "FA:7E:99:07:A4:1A:65:64:0E:63:10:7F:64:25:F2:23:87:5C:62:50" }, "basicConstraints": { "critical": true, "value": { "ca": false } }, "extendedKeyUsage": { "critical": false, "value": [ { "name": "id-kp-serverAuth", "oid": "1.3.6.1.5.5.7.3.1" }, { "name": "id-kp-clientAuth", "oid": "1.3.6.1.5.5.7.3.2" } ] }, "keyUsage": { "critical": false, "value": [ "key_encipherment", "digital_signature" ] }, "subjectAltName": { "critical": false, "value": [ { "name": "DNS", "value": "www.example.com" } ] }, "subjectKeyIdentifier": { "critical": false, "value": "72:C7:02:BB:FB:D4:F9:01:D5:87:44:59:39:9C:78:03:CA:E8:5B:30" } }, "key_size": 2048, "signature_algorithm": { "algorithm": "sha256WithRSAEncryption", "signature": "64:A4:A5:AC:C4:04:C7:3A:B0:E1:2E:DD:A2:FB:76:0E:A9:6F:3B:61:86:F0:C5:63:04:21:00:A8:85:CC:E0:D3:CF:69:3E:D3:E7:47:FC:F1:A8:83:91:4E:52:59:5C:72:F2:EF:5E:34:41:6D:FF:1E:DE:E1:8F:FA:96:06:99:EE:42:D8:F9:C5:73:76:92:03:D8:4F:AC:86:FD:FC:02:44:B4:38:34:A1:91:96:1E:6A:C5:E9:53:B5:69:0C:09:4E:70:96:14:99:97:BD:2D:17:4A:67:A5:13:2A:F0:E9:4C:29:D9:AE:57:D6:D1:78:00:CF:E8:D9:D3:32:A7:CB:7E:5F:31:4A:0E:29:D7:B4:BA:68:8F:A5:91:DD:50:E3:09:8E:DA:56:5E:87:7B:86:75:5F:D5:FB:FC:09:CC:14:82:6C:9E:59:58:64:66:44:73:54:BD:66:15:A8:23:B1:FB:A4:09:29:A6:CD:5E:56:19:B6:B4:62:7C:2F:89:3F:BD:04:BA:36:70:0D:AC:36:99:AC:88:3A:F2:CB:05:B7:81:ED:85:DC:8A:FC:09:CC:D1:EF:AD:D5:B4:77:A0:D2:78:FA:E6:18:1D:71:D1:3B:BD:BB:14:B6:91:64:3D:69:0B:87:8E:1B:98:10:65:30:61:97:79:B9:75:22:EB:79:C8" }, "subject": [ { "name": "commonName", "oid": "2.5.4.3", "value": "www.example.com" } ], "validity": { "not_valid_after": "20270228123909Z", "not_valid_before": "20260228123924Z" } } }, "changed": false } TASK [Verify certificate subject] ********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:99 Saturday 28 February 2026 07:39:30 -0500 (0:00:00.045) 0:00:14.706 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate SAN] ************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:107 Saturday 28 February 2026 07:39:30 -0500 (0:00:00.062) 0:00:14.769 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify key size] ********************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:115 Saturday 28 February 2026 07:39:30 -0500 (0:00:00.063) 0:00:14.833 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate Key Usage] ******************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:122 Saturday 28 February 2026 07:39:31 -0500 (0:00:00.069) 0:00:14.903 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate Extended Key Usage] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:133 Saturday 28 February 2026 07:39:31 -0500 (0:00:00.073) 0:00:14.976 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Retrieve auto-renew flag] ************************************************ task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:146 Saturday 28 February 2026 07:39:31 -0500 (0:00:00.076) 0:00:15.052 ***** ok: [managed-node2] => { "changed": false, "cmd": "set -euo pipefail; getcert list -f /etc/pki/tls/certs/certid.crt | grep 'auto-renew' | sed 's/^\\s\\+auto-renew: //g'", "delta": "0:00:00.039199", "end": "2026-02-28 07:39:31.510724", "rc": 0, "start": "2026-02-28 07:39:31.471525" } STDOUT: yes TASK [Verify certificate auto-renew flag] ************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:155 Saturday 28 February 2026 07:39:31 -0500 (0:00:00.353) 0:00:15.406 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Stat commands file] ****************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:163 Saturday 28 February 2026 07:39:31 -0500 (0:00:00.045) 0:00:15.451 ***** ok: [managed-node2] => { "changed": false, "stat": { "exists": false } } TASK [Assert that commands file got removed] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:168 Saturday 28 February 2026 07:39:31 -0500 (0:00:00.273) 0:00:15.725 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Stat first-boot unit file] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:176 Saturday 28 February 2026 07:39:31 -0500 (0:00:00.044) 0:00:15.769 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert presence of first-boot unit] ************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:181 Saturday 28 February 2026 07:39:31 -0500 (0:00:00.035) 0:00:15.805 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert that first-boot unit is enabled] ********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:186 Saturday 28 February 2026 07:39:31 -0500 (0:00:00.036) 0:00:15.841 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Stat commands file] ****************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:193 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.035) 0:00:15.877 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert that commands file exists] **************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:198 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.037) 0:00:15.914 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Issue certificate setting user/group/mode] ******************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:66 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.037) 0:00:15.952 ***** TASK [fedora.linux_system_roles.certificate : Set version specific variables] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:2 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.132) 0:00:16.085 ***** included: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml for managed-node2 TASK [fedora.linux_system_roles.certificate : Ensure ansible_facts used by role] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:2 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.027) 0:00:16.112 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Check if system is ostree] ******* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:10 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.043) 0:00:16.156 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Set flag to indicate system is ostree] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:15 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.050) 0:00:16.206 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Run systemctl] ******************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:22 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.056) 0:00:16.263 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Require installed systemd] ******* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:30 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.052) 0:00:16.316 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Set flag to indicate that systemd runtime operations are available] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:35 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.043) 0:00:16.359 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Set platform/version specific variables] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:40 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.044) 0:00:16.403 ***** skipping: [managed-node2] => (item=RedHat.yml) => { "ansible_loop_var": "item", "changed": false, "item": "RedHat.yml", "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=CentOS.yml) => { "ansible_loop_var": "item", "changed": false, "item": "CentOS.yml", "skip_reason": "Conditional result was False" } ok: [managed-node2] => (item=CentOS_7.yml) => { "ansible_facts": { "__certificate_default_directory": "/etc/pki/tls", "__certificate_packages": [ "python-pyasn1", "python-cryptography", "python-dbus" ] }, "ansible_included_var_files": [ "/tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/vars/CentOS_7.yml" ], "ansible_loop_var": "item", "changed": false, "item": "CentOS_7.yml" } skipping: [managed-node2] => (item=CentOS_7.9.yml) => { "ansible_loop_var": "item", "changed": false, "item": "CentOS_7.9.yml", "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Ensure certificate role dependencies are installed] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:5 Saturday 28 February 2026 07:39:32 -0500 (0:00:00.133) 0:00:16.537 ***** ok: [managed-node2] => { "changed": false, "rc": 0, "results": [ "python2-pyasn1-0.1.9-7.el7.noarch providing python-pyasn1 is already installed", "python2-cryptography-1.7.2-2.el7.x86_64 providing python-cryptography is already installed", "dbus-python-1.1.1-9.el7.x86_64 providing python-dbus is already installed" ] } lsrpackages: python-cryptography python-dbus python-pyasn1 TASK [fedora.linux_system_roles.certificate : Ensure provider packages are installed] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:15 Saturday 28 February 2026 07:39:33 -0500 (0:00:00.988) 0:00:17.526 ***** ok: [managed-node2] => (item=certmonger) => { "__certificate_provider": "certmonger", "ansible_loop_var": "__certificate_provider", "changed": false, "rc": 0, "results": [ "certmonger-0.78.4-17.el7_9.x86_64 providing certmonger is already installed" ] } lsrpackages: certmonger TASK [fedora.linux_system_roles.certificate : Ensure pre-scripts hooks directory exists] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:25 Saturday 28 February 2026 07:39:34 -0500 (0:00:00.571) 0:00:18.097 ***** ok: [managed-node2] => (item=certmonger) => { "__certificate_provider": "certmonger", "ansible_loop_var": "__certificate_provider", "changed": false, "gid": 0, "group": "root", "mode": "0700", "owner": "root", "path": "/etc/certmonger//pre-scripts", "secontext": "unconfined_u:object_r:etc_t:s0", "size": 4096, "state": "directory", "uid": 0 } TASK [fedora.linux_system_roles.certificate : Ensure post-scripts hooks directory exists] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:49 Saturday 28 February 2026 07:39:34 -0500 (0:00:00.332) 0:00:18.429 ***** ok: [managed-node2] => (item=certmonger) => { "__certificate_provider": "certmonger", "ansible_loop_var": "__certificate_provider", "changed": false, "gid": 0, "group": "root", "mode": "0700", "owner": "root", "path": "/etc/certmonger//post-scripts", "secontext": "unconfined_u:object_r:etc_t:s0", "size": 4096, "state": "directory", "uid": 0 } TASK [fedora.linux_system_roles.certificate : Ensure provider service is running] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:76 Saturday 28 February 2026 07:39:34 -0500 (0:00:00.376) 0:00:18.806 ***** ok: [managed-node2] => (item=certmonger) => { "__certificate_provider": "certmonger", "ansible_loop_var": "__certificate_provider", "changed": false, "enabled": true, "name": "certmonger", "state": "started", "status": { "ActiveEnterTimestamp": "Sat 2026-02-28 07:39:09 EST", "ActiveEnterTimestampMonotonic": "377827221", "ActiveExitTimestampMonotonic": "0", "ActiveState": "active", "After": "network.target system.slice systemd-journald.socket syslog.target basic.target dbus.service", "AllowIsolate": "no", "AmbientCapabilities": "0", "AssertResult": "yes", "AssertTimestamp": "Sat 2026-02-28 07:39:09 EST", "AssertTimestampMonotonic": "377799286", "Before": "multi-user.target shutdown.target", "BlockIOAccounting": "no", "BlockIOWeight": "18446744073709551615", "BusName": "org.fedorahosted.certmonger", "CPUAccounting": "no", "CPUQuotaPerSecUSec": "infinity", "CPUSchedulingPolicy": "0", "CPUSchedulingPriority": "0", "CPUSchedulingResetOnFork": "no", "CPUShares": "18446744073709551615", "CanIsolate": "no", "CanReload": "no", "CanStart": "yes", "CanStop": "yes", "CapabilityBoundingSet": "18446744073709551615", "CollectMode": "inactive", "ConditionResult": "yes", "ConditionTimestamp": "Sat 2026-02-28 07:39:09 EST", "ConditionTimestampMonotonic": "377799285", "Conflicts": "shutdown.target", "ControlGroup": "/system.slice/certmonger.service", "ControlPID": "0", "DefaultDependencies": "yes", "Delegate": "no", "Description": "Certificate monitoring and PKI enrollment", "DevicePolicy": "auto", "EnvironmentFile": "/etc/sysconfig/certmonger (ignore_errors=yes)", "ExecMainCode": "0", "ExecMainExitTimestampMonotonic": "0", "ExecMainPID": "9750", "ExecMainStartTimestamp": "Sat 2026-02-28 07:39:09 EST", "ExecMainStartTimestampMonotonic": "377799793", "ExecMainStatus": "0", "ExecStart": "{ path=/usr/sbin/certmonger ; argv[]=/usr/sbin/certmonger -S -p /var/run/certmonger.pid -n $OPTS ; ignore_errors=no ; start_time=[Sat 2026-02-28 07:39:09 EST] ; stop_time=[n/a] ; pid=9750 ; code=(null) ; status=0/0 }", "FailureAction": "none", "FileDescriptorStoreMax": "0", "FragmentPath": "/usr/lib/systemd/system/certmonger.service", "GuessMainPID": "yes", "IOScheduling": "0", "Id": "certmonger.service", "IgnoreOnIsolate": "no", "IgnoreOnSnapshot": "no", "IgnoreSIGPIPE": "yes", "InactiveEnterTimestampMonotonic": "0", "InactiveExitTimestamp": "Sat 2026-02-28 07:39:09 EST", "InactiveExitTimestampMonotonic": "377799819", "JobTimeoutAction": "none", "JobTimeoutUSec": "0", "KillMode": "control-group", "KillSignal": "15", "LimitAS": "18446744073709551615", "LimitCORE": "18446744073709551615", "LimitCPU": "18446744073709551615", "LimitDATA": "18446744073709551615", "LimitFSIZE": "18446744073709551615", "LimitLOCKS": "18446744073709551615", "LimitMEMLOCK": "65536", "LimitMSGQUEUE": "819200", "LimitNICE": "0", "LimitNOFILE": "4096", "LimitNPROC": "29173", "LimitRSS": "18446744073709551615", "LimitRTPRIO": "0", "LimitRTTIME": "18446744073709551615", "LimitSIGPENDING": "29173", "LimitSTACK": "18446744073709551615", "LoadState": "loaded", "MainPID": "9750", "MemoryAccounting": "no", "MemoryCurrent": "18446744073709551615", "MemoryLimit": "18446744073709551615", "MountFlags": "0", "Names": "certmonger.service", "NeedDaemonReload": "no", "Nice": "0", "NoNewPrivileges": "no", "NonBlocking": "no", "NotifyAccess": "none", "OOMScoreAdjust": "0", "OnFailureJobMode": "replace", "PIDFile": "/var/run/certmonger.pid", "PermissionsStartOnly": "no", "PrivateDevices": "no", "PrivateNetwork": "no", "PrivateTmp": "no", "ProtectHome": "no", "ProtectSystem": "no", "RefuseManualStart": "no", "RefuseManualStop": "no", "RemainAfterExit": "no", "Requires": "basic.target system.slice", "Restart": "no", "RestartUSec": "100ms", "Result": "success", "RootDirectoryStartOnly": "no", "RuntimeDirectoryMode": "0755", "SameProcessGroup": "no", "SecureBits": "0", "SendSIGHUP": "no", "SendSIGKILL": "yes", "Slice": "system.slice", "StandardError": "inherit", "StandardInput": "null", "StandardOutput": "journal", "StartLimitAction": "none", "StartLimitBurst": "5", "StartLimitInterval": "10000000", "StartupBlockIOWeight": "18446744073709551615", "StartupCPUShares": "18446744073709551615", "StatusErrno": "0", "StopWhenUnneeded": "no", "SubState": "running", "SyslogLevelPrefix": "yes", "SyslogPriority": "30", "SystemCallErrorNumber": "0", "TTYReset": "no", "TTYVHangup": "no", "TTYVTDisallocate": "no", "TasksAccounting": "no", "TasksCurrent": "18446744073709551615", "TasksMax": "18446744073709551615", "TimeoutStartUSec": "1min 30s", "TimeoutStopUSec": "1min 30s", "TimerSlackNSec": "50000", "Transient": "no", "Type": "dbus", "UMask": "0022", "UnitFilePreset": "disabled", "UnitFileState": "enabled", "WantedBy": "multi-user.target", "WatchdogTimestamp": "Sat 2026-02-28 07:39:09 EST", "WatchdogTimestampMonotonic": "377827189", "WatchdogUSec": "0" } } TASK [fedora.linux_system_roles.certificate : Ensure certificate requests] ***** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:86 Saturday 28 February 2026 07:39:35 -0500 (0:00:00.472) 0:00:19.278 ***** changed: [managed-node2] => (item={u'group': u'ftp', u'name': u'mycert_fs_attrs_mode', u'dns': u'www.example.com', u'owner': u'ftp', u'ca': u'self-sign', u'mode': u'0620'}) => { "ansible_loop_var": "item", "changed": true, "item": { "ca": "self-sign", "dns": "www.example.com", "group": "ftp", "mode": "0620", "name": "mycert_fs_attrs_mode", "owner": "ftp" } } MSG: Certificate requested (new). File attributes updated. changed: [managed-node2] => (item={u'ca': u'self-sign', u'name': u'certid_mode', u'dns': u'www.example.com', u'mode': u'0o600'}) => { "ansible_loop_var": "item", "changed": true, "item": { "ca": "self-sign", "dns": "www.example.com", "mode": "0o600", "name": "certid_mode" } } MSG: Certificate requested (new). TASK [fedora.linux_system_roles.certificate : Check if test mode is supported] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:138 Saturday 28 February 2026 07:39:36 -0500 (0:00:01.478) 0:00:20.757 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Slurp the contents of the files] *** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:143 Saturday 28 February 2026 07:39:36 -0500 (0:00:00.053) 0:00:20.810 ***** skipping: [managed-node2] => (item=[u'cert', {u'group': u'ftp', u'name': u'mycert_fs_attrs_mode', u'dns': u'www.example.com', u'owner': u'ftp', u'ca': u'self-sign', u'mode': u'0620'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "cert", { "ca": "self-sign", "dns": "www.example.com", "group": "ftp", "mode": "0620", "name": "mycert_fs_attrs_mode", "owner": "ftp" } ], "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=[u'cert', {u'ca': u'self-sign', u'name': u'certid_mode', u'dns': u'www.example.com', u'mode': u'0o600'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "cert", { "ca": "self-sign", "dns": "www.example.com", "mode": "0o600", "name": "certid_mode" } ], "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=[u'key', {u'group': u'ftp', u'name': u'mycert_fs_attrs_mode', u'dns': u'www.example.com', u'owner': u'ftp', u'ca': u'self-sign', u'mode': u'0620'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "key", { "ca": "self-sign", "dns": "www.example.com", "group": "ftp", "mode": "0620", "name": "mycert_fs_attrs_mode", "owner": "ftp" } ], "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=[u'key', {u'ca': u'self-sign', u'name': u'certid_mode', u'dns': u'www.example.com', u'mode': u'0o600'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "key", { "ca": "self-sign", "dns": "www.example.com", "mode": "0o600", "name": "certid_mode" } ], "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=[u'ca', {u'group': u'ftp', u'name': u'mycert_fs_attrs_mode', u'dns': u'www.example.com', u'owner': u'ftp', u'ca': u'self-sign', u'mode': u'0620'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "ca", { "ca": "self-sign", "dns": "www.example.com", "group": "ftp", "mode": "0620", "name": "mycert_fs_attrs_mode", "owner": "ftp" } ], "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=[u'ca', {u'ca': u'self-sign', u'name': u'certid_mode', u'dns': u'www.example.com', u'mode': u'0o600'}]) => { "ansible_loop_var": "item", "changed": false, "item": [ "ca", { "ca": "self-sign", "dns": "www.example.com", "mode": "0o600", "name": "certid_mode" } ], "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Reset certificate_test_certs] **** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:151 Saturday 28 February 2026 07:39:37 -0500 (0:00:00.108) 0:00:20.918 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Create return data] ************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:155 Saturday 28 February 2026 07:39:37 -0500 (0:00:00.053) 0:00:20.972 ***** skipping: [managed-node2] => (item=certid_mode) => { "ansible_loop_var": "cert_name", "cert_name": "certid_mode", "changed": false, "skip_reason": "Conditional result was False" } skipping: [managed-node2] => (item=mycert_fs_attrs_mode) => { "ansible_loop_var": "cert_name", "cert_name": "mycert_fs_attrs_mode", "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Stop tracking certificates] ****** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:169 Saturday 28 February 2026 07:39:37 -0500 (0:00:00.104) 0:00:21.076 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [fedora.linux_system_roles.certificate : Remove files] ******************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:174 Saturday 28 February 2026 07:39:37 -0500 (0:00:00.047) 0:00:21.123 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Create QEMU deployment during bootc end-to-end test] ********************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:85 Saturday 28 February 2026 07:39:37 -0500 (0:00:00.049) 0:00:21.173 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Verify each fs_attrs_mode certificate] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:92 Saturday 28 February 2026 07:39:37 -0500 (0:00:00.061) 0:00:21.235 ***** included: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml for managed-node2 included: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml for managed-node2 TASK [Set virtualenv_path] ***************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:5 Saturday 28 February 2026 07:39:37 -0500 (0:00:00.206) 0:00:21.441 ***** ok: [managed-node2] => { "ansible_facts": { "__virtualenv_path": "/tmp/certificate-tests-venv" }, "changed": false } TASK [Check if system is ostree] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:12 Saturday 28 February 2026 07:39:37 -0500 (0:00:00.057) 0:00:21.499 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Set flag to indicate system is ostree] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:17 Saturday 28 February 2026 07:39:37 -0500 (0:00:00.042) 0:00:21.542 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Ensure python2 is installed] ********************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:21 Saturday 28 February 2026 07:39:37 -0500 (0:00:00.045) 0:00:21.587 ***** ok: [managed-node2] => { "changed": false, "rc": 0, "results": [ "python2-cryptography-1.7.2-2.el7.x86_64 providing python2-cryptography is already installed", "python2-cryptography-1.7.2-2.el7.x86_64 providing python2-cryptography is already installed" ] } lsrpackages: python2-cryptography TASK [Ensure python3 is installed] ********************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:31 Saturday 28 February 2026 07:39:38 -0500 (0:00:00.547) 0:00:22.134 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Retrieve certificate file stats] ***************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:41 Saturday 28 February 2026 07:39:38 -0500 (0:00:00.045) 0:00:22.180 ***** ok: [managed-node2] => { "changed": false, "stat": { "atime": 1772282376.0783849, "attr_flags": "e", "attributes": [ "extents" ], "block_size": 4096, "blocks": 8, "charset": "us-ascii", "checksum": "4bf4a84982a36633f96b667393b46fb0b0164269", "ctime": 1772282376.1473854, "dev": 51713, "device_type": 0, "executable": false, "exists": true, "gid": 50, "gr_name": "ftp", "inode": 172749, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0620", "mtime": 1772282376.074385, "nlink": 1, "path": "/etc/pki/tls/certs/mycert_fs_attrs_mode.crt", "pw_name": "ftp", "readable": true, "rgrp": false, "roth": false, "rusr": true, "size": 1294, "uid": 14, "version": "18446744072279692349", "wgrp": true, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false } } TASK [Verify if certificate file exists] *************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:46 Saturday 28 February 2026 07:39:38 -0500 (0:00:00.333) 0:00:22.513 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate file owner and group] ********************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:52 Saturday 28 February 2026 07:39:38 -0500 (0:00:00.065) 0:00:22.579 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate permissions] ****************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:62 Saturday 28 February 2026 07:39:38 -0500 (0:00:00.058) 0:00:22.638 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Retrieve key file stats] ************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:68 Saturday 28 February 2026 07:39:38 -0500 (0:00:00.053) 0:00:22.692 ***** ok: [managed-node2] => { "changed": false, "stat": { "atime": 1772282376.0353847, "attr_flags": "e", "attributes": [ "extents" ], "block_size": 4096, "blocks": 8, "charset": "us-ascii", "checksum": "b034412361f552bffe7572f54fbd87003e148398", "ctime": 1772282376.1473854, "dev": 51713, "device_type": 0, "executable": false, "exists": true, "gid": 50, "gr_name": "ftp", "inode": 172748, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0620", "mtime": 1772282376.074385, "nlink": 1, "path": "/etc/pki/tls/private/mycert_fs_attrs_mode.key", "pw_name": "ftp", "readable": true, "rgrp": false, "roth": false, "rusr": true, "size": 1704, "uid": 14, "version": "18446744072279692336", "wgrp": true, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false } } TASK [Verify if key file exists] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:73 Saturday 28 February 2026 07:39:39 -0500 (0:00:00.328) 0:00:23.020 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify key file owner and group] ***************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:79 Saturday 28 February 2026 07:39:39 -0500 (0:00:00.048) 0:00:23.069 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Parse certificate] ******************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:89 Saturday 28 February 2026 07:39:39 -0500 (0:00:00.061) 0:00:23.130 ***** ok: [managed-node2] => { "certificate": { "extensions": { "authorityKeyIdentifier": { "critical": false, "value": "FA:7E:99:07:A4:1A:65:64:0E:63:10:7F:64:25:F2:23:87:5C:62:50" }, "basicConstraints": { "critical": true, "value": { "ca": false } }, "extendedKeyUsage": { "critical": false, "value": [ { "name": "id-kp-serverAuth", "oid": "1.3.6.1.5.5.7.3.1" }, { "name": "id-kp-clientAuth", "oid": "1.3.6.1.5.5.7.3.2" } ] }, "keyUsage": { "critical": false, "value": [ "key_encipherment", "digital_signature" ] }, "subjectAltName": { "critical": false, "value": [ { "name": "DNS", "value": "www.example.com" } ] }, "subjectKeyIdentifier": { "critical": false, "value": "62:8C:33:51:07:2D:5F:C7:91:0B:90:93:6D:85:9C:4A:AE:48:31:94" } }, "key_size": 2048, "signature_algorithm": { "algorithm": "sha256WithRSAEncryption", "signature": "58:79:AC:F6:1A:6E:E3:1C:A3:E2:94:5A:00:23:0E:1D:6D:FF:1B:11:EB:FF:A9:34:15:CE:95:FE:FF:62:DF:0D:0C:A1:35:82:DA:45:41:E0:4C:54:36:F9:9F:24:DF:31:59:17:32:A5:62:F6:F7:36:36:CB:7C:27:E9:67:58:51:84:A6:2E:C8:2C:8E:24:2D:3D:F2:8B:0C:7C:8D:E6:B8:51:35:49:76:A7:0D:C8:FC:29:77:8C:E3:0C:F3:5B:EC:C2:D9:67:2E:8C:90:E1:44:3E:CA:CB:58:BE:DE:CD:65:6E:2F:5F:96:A5:BF:8D:70:10:CF:F2:DB:57:35:3D:E1:F5:54:0E:1B:A7:0B:EC:1D:0F:8E:BD:E7:EB:74:0C:DC:CB:8E:BE:28:EF:A6:C5:6B:4E:EF:02:82:36:B5:E6:68:E3:C9:37:58:37:B0:91:8A:C6:FA:B0:C4:45:69:DE:D8:A3:0B:D4:31:40:69:59:A6:13:0E:FE:09:6A:49:D4:0F:6B:14:9A:EE:C7:D1:6D:07:91:44:44:AD:86:7D:7B:D5:F5:F6:1F:2A:AF:63:E8:66:3C:EF:7B:68:39:D6:75:28:67:67:01:0B:D3:9E:80:90:CB:D3:C2:3B:69:79:BF:4C:AE:5D:45:70:F5:C1:24:ED:D6:6B:67:36:6B:27:FF:4A" }, "subject": [ { "name": "commonName", "oid": "2.5.4.3", "value": "www.example.com" } ], "validity": { "not_valid_after": "20270228123909Z", "not_valid_before": "20260228123936Z" } }, "changed": false } TASK [Load certificate YAML to cert_issued variable] *************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:95 Saturday 28 February 2026 07:39:39 -0500 (0:00:00.368) 0:00:23.498 ***** ok: [managed-node2] => { "ansible_facts": { "cert_issued": { "extensions": { "authorityKeyIdentifier": { "critical": false, "value": "FA:7E:99:07:A4:1A:65:64:0E:63:10:7F:64:25:F2:23:87:5C:62:50" }, "basicConstraints": { "critical": true, "value": { "ca": false } }, "extendedKeyUsage": { "critical": false, "value": [ { "name": "id-kp-serverAuth", "oid": "1.3.6.1.5.5.7.3.1" }, { "name": "id-kp-clientAuth", "oid": "1.3.6.1.5.5.7.3.2" } ] }, "keyUsage": { "critical": false, "value": [ "key_encipherment", "digital_signature" ] }, "subjectAltName": { "critical": false, "value": [ { "name": "DNS", "value": "www.example.com" } ] }, "subjectKeyIdentifier": { "critical": false, "value": "62:8C:33:51:07:2D:5F:C7:91:0B:90:93:6D:85:9C:4A:AE:48:31:94" } }, "key_size": 2048, "signature_algorithm": { "algorithm": "sha256WithRSAEncryption", "signature": "58:79:AC:F6:1A:6E:E3:1C:A3:E2:94:5A:00:23:0E:1D:6D:FF:1B:11:EB:FF:A9:34:15:CE:95:FE:FF:62:DF:0D:0C:A1:35:82:DA:45:41:E0:4C:54:36:F9:9F:24:DF:31:59:17:32:A5:62:F6:F7:36:36:CB:7C:27:E9:67:58:51:84:A6:2E:C8:2C:8E:24:2D:3D:F2:8B:0C:7C:8D:E6:B8:51:35:49:76:A7:0D:C8:FC:29:77:8C:E3:0C:F3:5B:EC:C2:D9:67:2E:8C:90:E1:44:3E:CA:CB:58:BE:DE:CD:65:6E:2F:5F:96:A5:BF:8D:70:10:CF:F2:DB:57:35:3D:E1:F5:54:0E:1B:A7:0B:EC:1D:0F:8E:BD:E7:EB:74:0C:DC:CB:8E:BE:28:EF:A6:C5:6B:4E:EF:02:82:36:B5:E6:68:E3:C9:37:58:37:B0:91:8A:C6:FA:B0:C4:45:69:DE:D8:A3:0B:D4:31:40:69:59:A6:13:0E:FE:09:6A:49:D4:0F:6B:14:9A:EE:C7:D1:6D:07:91:44:44:AD:86:7D:7B:D5:F5:F6:1F:2A:AF:63:E8:66:3C:EF:7B:68:39:D6:75:28:67:67:01:0B:D3:9E:80:90:CB:D3:C2:3B:69:79:BF:4C:AE:5D:45:70:F5:C1:24:ED:D6:6B:67:36:6B:27:FF:4A" }, "subject": [ { "name": "commonName", "oid": "2.5.4.3", "value": "www.example.com" } ], "validity": { "not_valid_after": "20270228123909Z", "not_valid_before": "20260228123936Z" } } }, "changed": false } TASK [Verify certificate subject] ********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:99 Saturday 28 February 2026 07:39:39 -0500 (0:00:00.067) 0:00:23.565 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate SAN] ************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:107 Saturday 28 February 2026 07:39:39 -0500 (0:00:00.069) 0:00:23.635 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify key size] ********************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:115 Saturday 28 February 2026 07:39:39 -0500 (0:00:00.053) 0:00:23.688 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate Key Usage] ******************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:122 Saturday 28 February 2026 07:39:39 -0500 (0:00:00.047) 0:00:23.736 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate Extended Key Usage] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:133 Saturday 28 February 2026 07:39:39 -0500 (0:00:00.051) 0:00:23.787 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Retrieve auto-renew flag] ************************************************ task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:146 Saturday 28 February 2026 07:39:39 -0500 (0:00:00.049) 0:00:23.837 ***** ok: [managed-node2] => { "changed": false, "cmd": "set -euo pipefail; getcert list -f /etc/pki/tls/certs/mycert_fs_attrs_mode.crt | grep 'auto-renew' | sed 's/^\\s\\+auto-renew: //g'", "delta": "0:00:00.042114", "end": "2026-02-28 07:39:40.264329", "rc": 0, "start": "2026-02-28 07:39:40.222215" } STDOUT: yes TASK [Verify certificate auto-renew flag] ************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:155 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.324) 0:00:24.161 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Stat commands file] ****************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:163 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.047) 0:00:24.208 ***** ok: [managed-node2] => { "changed": false, "stat": { "exists": false } } TASK [Assert that commands file got removed] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:168 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.283) 0:00:24.492 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Stat first-boot unit file] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:176 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.056) 0:00:24.549 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert presence of first-boot unit] ************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:181 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.053) 0:00:24.602 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert that first-boot unit is enabled] ********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:186 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.041) 0:00:24.644 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Stat commands file] ****************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:193 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.046) 0:00:24.690 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert that commands file exists] **************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:198 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.047) 0:00:24.737 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Set virtualenv_path] ***************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:5 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.043) 0:00:24.781 ***** ok: [managed-node2] => { "ansible_facts": { "__virtualenv_path": "/tmp/certificate-tests-venv" }, "changed": false } TASK [Check if system is ostree] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:12 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.040) 0:00:24.821 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Set flag to indicate system is ostree] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:17 Saturday 28 February 2026 07:39:40 -0500 (0:00:00.039) 0:00:24.860 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Ensure python2 is installed] ********************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:21 Saturday 28 February 2026 07:39:41 -0500 (0:00:00.038) 0:00:24.899 ***** ok: [managed-node2] => { "changed": false, "rc": 0, "results": [ "python2-cryptography-1.7.2-2.el7.x86_64 providing python2-cryptography is already installed", "python2-cryptography-1.7.2-2.el7.x86_64 providing python2-cryptography is already installed" ] } lsrpackages: python2-cryptography TASK [Ensure python3 is installed] ********************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:31 Saturday 28 February 2026 07:39:41 -0500 (0:00:00.573) 0:00:25.472 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Retrieve certificate file stats] ***************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:41 Saturday 28 February 2026 07:39:41 -0500 (0:00:00.049) 0:00:25.522 ***** ok: [managed-node2] => { "changed": false, "stat": { "atime": 1772282376.6883883, "attr_flags": "e", "attributes": [ "extents" ], "block_size": 4096, "blocks": 8, "charset": "us-ascii", "checksum": "275afe40e1db49b353f491ec23c36b00fce359da", "ctime": 1772282376.6843882, "dev": 51713, "device_type": 0, "executable": false, "exists": true, "gid": 0, "gr_name": "root", "inode": 172754, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0600", "mtime": 1772282376.6843882, "nlink": 1, "path": "/etc/pki/tls/certs/certid_mode.crt", "pw_name": "root", "readable": true, "rgrp": false, "roth": false, "rusr": true, "size": 1294, "uid": 0, "version": "18446744072279692387", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false } } TASK [Verify if certificate file exists] *************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:46 Saturday 28 February 2026 07:39:41 -0500 (0:00:00.329) 0:00:25.851 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate file owner and group] ********************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:52 Saturday 28 February 2026 07:39:42 -0500 (0:00:00.055) 0:00:25.906 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate permissions] ****************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:62 Saturday 28 February 2026 07:39:42 -0500 (0:00:00.074) 0:00:25.981 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Retrieve key file stats] ************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:68 Saturday 28 February 2026 07:39:42 -0500 (0:00:00.060) 0:00:26.041 ***** ok: [managed-node2] => { "changed": false, "stat": { "atime": 1772282376.6453881, "attr_flags": "e", "attributes": [ "extents" ], "block_size": 4096, "blocks": 8, "charset": "us-ascii", "checksum": "5f204716d76400a8e1dbc8de8dd0435d5528e0ed", "ctime": 1772282376.6843882, "dev": 51713, "device_type": 0, "executable": false, "exists": true, "gid": 0, "gr_name": "root", "inode": 172750, "isblk": false, "ischr": false, "isdir": false, "isfifo": false, "isgid": false, "islnk": false, "isreg": true, "issock": false, "isuid": false, "mimetype": "text/plain", "mode": "0600", "mtime": 1772282376.6843882, "nlink": 1, "path": "/etc/pki/tls/private/certid_mode.key", "pw_name": "root", "readable": true, "rgrp": false, "roth": false, "rusr": true, "size": 1704, "uid": 0, "version": "18446744072279692374", "wgrp": false, "woth": false, "writeable": true, "wusr": true, "xgrp": false, "xoth": false, "xusr": false } } TASK [Verify if key file exists] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:73 Saturday 28 February 2026 07:39:42 -0500 (0:00:00.306) 0:00:26.347 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify key file owner and group] ***************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:79 Saturday 28 February 2026 07:39:42 -0500 (0:00:00.065) 0:00:26.412 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Parse certificate] ******************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:89 Saturday 28 February 2026 07:39:42 -0500 (0:00:00.063) 0:00:26.476 ***** ok: [managed-node2] => { "certificate": { "extensions": { "authorityKeyIdentifier": { "critical": false, "value": "FA:7E:99:07:A4:1A:65:64:0E:63:10:7F:64:25:F2:23:87:5C:62:50" }, "basicConstraints": { "critical": true, "value": { "ca": false } }, "extendedKeyUsage": { "critical": false, "value": [ { "name": "id-kp-serverAuth", "oid": "1.3.6.1.5.5.7.3.1" }, { "name": "id-kp-clientAuth", "oid": "1.3.6.1.5.5.7.3.2" } ] }, "keyUsage": { "critical": false, "value": [ "key_encipherment", "digital_signature" ] }, "subjectAltName": { "critical": false, "value": [ { "name": "DNS", "value": "www.example.com" } ] }, "subjectKeyIdentifier": { "critical": false, "value": "26:18:6C:69:46:A5:59:0B:00:44:AB:D0:F4:7D:E3:58:B9:9D:A5:87" } }, "key_size": 2048, "signature_algorithm": { "algorithm": "sha256WithRSAEncryption", "signature": "5D:B3:9C:90:84:DC:FC:49:54:19:4A:71:22:56:9D:78:EB:B3:D3:60:F2:98:C9:08:95:11:2B:B9:13:03:7D:8E:09:29:9B:6A:F2:79:EC:72:A7:5B:A7:9A:2A:A5:15:15:46:E1:3B:52:B0:CE:CB:F4:EF:2D:39:FA:33:D8:E0:51:AA:B4:24:B8:D5:62:EE:1D:AC:52:B1:18:46:A0:D4:94:12:C7:56:B8:D7:B7:81:FF:3E:16:30:FB:14:2F:2C:53:08:62:A9:D0:54:3E:AF:22:B4:96:05:55:EC:E0:B2:14:8A:AD:38:42:2F:CC:25:1D:19:65:80:22:EB:4A:8D:73:F0:47:D7:81:A7:73:C9:F0:00:66:68:FD:1F:72:51:9E:A4:A5:3E:77:31:EF:6C:F4:4F:6E:E7:DF:1B:A7:9E:13:86:14:34:D2:3E:3D:10:25:7D:86:98:6C:CC:D8:5D:F6:24:81:00:66:E5:5A:6A:DA:9D:FE:35:D3:BB:A8:48:FF:EF:9B:C7:B6:3A:01:E9:65:FF:26:C6:DC:A8:E6:D6:7F:84:A1:91:E4:06:75:D6:45:00:DD:C5:67:DB:97:E0:7F:85:68:AC:3B:64:77:28:2F:91:60:3E:5E:4A:05:9D:24:CB:8A:F6:0D:C0:7C:58:1A:90:21:2F:8D:01:AB:17:58" }, "subject": [ { "name": "commonName", "oid": "2.5.4.3", "value": "www.example.com" } ], "validity": { "not_valid_after": "20270228123909Z", "not_valid_before": "20260228123936Z" } }, "changed": false } TASK [Load certificate YAML to cert_issued variable] *************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:95 Saturday 28 February 2026 07:39:42 -0500 (0:00:00.372) 0:00:26.848 ***** ok: [managed-node2] => { "ansible_facts": { "cert_issued": { "extensions": { "authorityKeyIdentifier": { "critical": false, "value": "FA:7E:99:07:A4:1A:65:64:0E:63:10:7F:64:25:F2:23:87:5C:62:50" }, "basicConstraints": { "critical": true, "value": { "ca": false } }, "extendedKeyUsage": { "critical": false, "value": [ { "name": "id-kp-serverAuth", "oid": "1.3.6.1.5.5.7.3.1" }, { "name": "id-kp-clientAuth", "oid": "1.3.6.1.5.5.7.3.2" } ] }, "keyUsage": { "critical": false, "value": [ "key_encipherment", "digital_signature" ] }, "subjectAltName": { "critical": false, "value": [ { "name": "DNS", "value": "www.example.com" } ] }, "subjectKeyIdentifier": { "critical": false, "value": "26:18:6C:69:46:A5:59:0B:00:44:AB:D0:F4:7D:E3:58:B9:9D:A5:87" } }, "key_size": 2048, "signature_algorithm": { "algorithm": "sha256WithRSAEncryption", "signature": "5D:B3:9C:90:84:DC:FC:49:54:19:4A:71:22:56:9D:78:EB:B3:D3:60:F2:98:C9:08:95:11:2B:B9:13:03:7D:8E:09:29:9B:6A:F2:79:EC:72:A7:5B:A7:9A:2A:A5:15:15:46:E1:3B:52:B0:CE:CB:F4:EF:2D:39:FA:33:D8:E0:51:AA:B4:24:B8:D5:62:EE:1D:AC:52:B1:18:46:A0:D4:94:12:C7:56:B8:D7:B7:81:FF:3E:16:30:FB:14:2F:2C:53:08:62:A9:D0:54:3E:AF:22:B4:96:05:55:EC:E0:B2:14:8A:AD:38:42:2F:CC:25:1D:19:65:80:22:EB:4A:8D:73:F0:47:D7:81:A7:73:C9:F0:00:66:68:FD:1F:72:51:9E:A4:A5:3E:77:31:EF:6C:F4:4F:6E:E7:DF:1B:A7:9E:13:86:14:34:D2:3E:3D:10:25:7D:86:98:6C:CC:D8:5D:F6:24:81:00:66:E5:5A:6A:DA:9D:FE:35:D3:BB:A8:48:FF:EF:9B:C7:B6:3A:01:E9:65:FF:26:C6:DC:A8:E6:D6:7F:84:A1:91:E4:06:75:D6:45:00:DD:C5:67:DB:97:E0:7F:85:68:AC:3B:64:77:28:2F:91:60:3E:5E:4A:05:9D:24:CB:8A:F6:0D:C0:7C:58:1A:90:21:2F:8D:01:AB:17:58" }, "subject": [ { "name": "commonName", "oid": "2.5.4.3", "value": "www.example.com" } ], "validity": { "not_valid_after": "20270228123909Z", "not_valid_before": "20260228123936Z" } } }, "changed": false } TASK [Verify certificate subject] ********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:99 Saturday 28 February 2026 07:39:43 -0500 (0:00:00.067) 0:00:26.916 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate SAN] ************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:107 Saturday 28 February 2026 07:39:43 -0500 (0:00:00.057) 0:00:26.973 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify key size] ********************************************************* task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:115 Saturday 28 February 2026 07:39:43 -0500 (0:00:00.053) 0:00:27.027 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate Key Usage] ******************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:122 Saturday 28 February 2026 07:39:43 -0500 (0:00:00.047) 0:00:27.074 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Verify certificate Extended Key Usage] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:133 Saturday 28 February 2026 07:39:43 -0500 (0:00:00.049) 0:00:27.123 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Retrieve auto-renew flag] ************************************************ task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:146 Saturday 28 February 2026 07:39:43 -0500 (0:00:00.051) 0:00:27.175 ***** ok: [managed-node2] => { "changed": false, "cmd": "set -euo pipefail; getcert list -f /etc/pki/tls/certs/certid_mode.crt | grep 'auto-renew' | sed 's/^\\s\\+auto-renew: //g'", "delta": "0:00:00.042654", "end": "2026-02-28 07:39:43.636877", "rc": 0, "start": "2026-02-28 07:39:43.594223" } STDOUT: yes TASK [Verify certificate auto-renew flag] ************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:155 Saturday 28 February 2026 07:39:43 -0500 (0:00:00.375) 0:00:27.550 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Stat commands file] ****************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:163 Saturday 28 February 2026 07:39:43 -0500 (0:00:00.056) 0:00:27.606 ***** ok: [managed-node2] => { "changed": false, "stat": { "exists": false } } TASK [Assert that commands file got removed] *********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:168 Saturday 28 February 2026 07:39:44 -0500 (0:00:00.293) 0:00:27.900 ***** ok: [managed-node2] => { "changed": false } MSG: All assertions passed TASK [Stat first-boot unit file] *********************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:176 Saturday 28 February 2026 07:39:44 -0500 (0:00:00.062) 0:00:27.963 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert presence of first-boot unit] ************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:181 Saturday 28 February 2026 07:39:44 -0500 (0:00:00.049) 0:00:28.013 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert that first-boot unit is enabled] ********************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:186 Saturday 28 February 2026 07:39:44 -0500 (0:00:00.037) 0:00:28.051 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Stat commands file] ****************************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:193 Saturday 28 February 2026 07:39:44 -0500 (0:00:00.036) 0:00:28.088 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } TASK [Assert that commands file exists] **************************************** task path: /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:198 Saturday 28 February 2026 07:39:44 -0500 (0:00:00.036) 0:00:28.124 ***** skipping: [managed-node2] => { "changed": false, "skip_reason": "Conditional result was False" } META: ran handlers META: ran handlers PLAY RECAP ********************************************************************* managed-node2 : ok=107 changed=4 unreachable=0 failed=0 skipped=53 rescued=0 ignored=0 SYSTEM ROLES ERRORS BEGIN v1 [] SYSTEM ROLES ERRORS END v1 TASKS RECAP ******************************************************************** Saturday 28 February 2026 07:39:44 -0500 (0:00:00.033) 0:00:28.157 ***** =============================================================================== fedora.linux_system_roles.certificate : Ensure certificate requests ----- 1.62s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:86 fedora.linux_system_roles.certificate : Ensure certificate requests ----- 1.48s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:86 fedora.linux_system_roles.certificate : Ensure certificate role dependencies are installed --- 1.18s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:5 fedora.linux_system_roles.certificate : Ensure certificate role dependencies are installed --- 0.99s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:5 Gathering Facts --------------------------------------------------------- 0.97s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:2 fedora.linux_system_roles.certificate : Ensure provider service is running --- 0.65s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:76 Ensure python2 is installed --------------------------------------------- 0.61s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:21 Parse certificate ------------------------------------------------------- 0.59s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:89 Ensure python2 is installed --------------------------------------------- 0.59s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:21 Ensure python2 is installed --------------------------------------------- 0.57s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:21 fedora.linux_system_roles.certificate : Ensure provider packages are installed --- 0.57s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:15 fedora.linux_system_roles.certificate : Ensure provider packages are installed --- 0.56s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:15 Ensure python2 is installed --------------------------------------------- 0.55s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:21 Ensure user exists ------------------------------------------------------ 0.53s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:5 Retrieve certificate file stats ----------------------------------------- 0.52s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tasks/assert_certificate_parameters.yml:41 Ensure group "somegroup" exists ----------------------------------------- 0.50s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/tests/certificate/tests_fs_attrs.yml:11 fedora.linux_system_roles.certificate : Ensure provider service is running --- 0.47s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:76 fedora.linux_system_roles.certificate : Ensure pre-scripts hooks directory exists --- 0.46s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/main.yml:25 fedora.linux_system_roles.certificate : Check if system is ostree ------- 0.44s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:10 fedora.linux_system_roles.certificate : Run systemctl ------------------- 0.40s /tmp/collections-klM/ansible_collections/fedora/linux_system_roles/roles/certificate/tasks/set_vars.yml:22