diff --git a/roles/vault/defaults/main.yml b/roles/vault/defaults/main.yml
index acd2ac8fd338c43d5c0ad2242ebb35bdad8e3d16..1f4a78b37cc4f6b718b9441f3e9efc9af66781d7 100644
--- a/roles/vault/defaults/main.yml
+++ b/roles/vault/defaults/main.yml
@@ -84,7 +84,7 @@ vault_ca_options:
     format: pem
     ttl: "{{ vault_max_lease_ttl }}"
     exclude_cn_from_sans: true
-    altnames:
+    alt_names:
       - "vault.{{ system_namespace }}.svc.{{ dns_domain }}"
       - "vault.{{ system_namespace }}.svc"
       - "vault.{{ system_namespace }}"
diff --git a/roles/vault/tasks/bootstrap/gen_vault_certs.yml b/roles/vault/tasks/bootstrap/gen_vault_certs.yml
index 8a82e5b6f55a3fe5a812bdef79664e60871b6db8..d542ef8454a09600b9147324d03635e6a2a57346 100644
--- a/roles/vault/tasks/bootstrap/gen_vault_certs.yml
+++ b/roles/vault/tasks/bootstrap/gen_vault_certs.yml
@@ -2,7 +2,7 @@
 - include: ../shared/issue_cert.yml
   vars:
     issue_cert_common_name: "{{ vault_pki_mounts.vault.roles[0].name }}"
-    issue_cert_alt_names: "{{ groups.vault + ['localhost'] + vault_ca_options.vault.altnames|default() }}"
+    issue_cert_alt_names: "{{ groups.vault + ['localhost'] + vault_ca_options.vault.alt_names|default() }}"
     issue_cert_hosts: "{{ groups.vault }}"
     issue_cert_ip_sans: >-
         [