Generate per-site SSL intermediate CA, fix cred/pki paths

Change-Id: I0bda0791d82142acac8c6af0e152d8d0954ef719
diff --git a/roles/ssh-pki/defaults/main.yml b/roles/ssh-pki/defaults/main.yml
index 1e8574e..c7e6125 100644
--- a/roles/ssh-pki/defaults/main.yml
+++ b/roles/ssh-pki/defaults/main.yml
@@ -1,9 +1,8 @@
 ---
 # ssh-pki/tasks/main.yml
 
-pki_dir: "/opt/pki"
-ssh_pki_dir: "/opt/ssh_pki"
-credentials_dir: "/opt/credentials"
+ssh_pki_dir: "{{ playbook_dir }}/ssh_pki"
+credentials_dir: "{{ playbook_dir }}/credentials"
 
 # password on SSH CA
 ssh_ca_phrase: "{{ lookup('password', credentials_dir ~ '/ssh_ca_phrase length=64') }}"