k8s ca apiserver kubelet 签发证书
2021-05-18 05:29
标签:ast min ext etc extension pen sub day src 3节点 192.168.52.6 master 192.168.52.7 node1 192.168.52.8 node2 /etc/ssl/k8s openssl genrsa -out ca.key 3072 解压签发证书所需文件 百度网盘提供 https://pan.baidu.com/s/1K_A6T8SwuinzQiOosCV6QA openssl req -x509 -new -key ca.key -days 10950 -out ca.pem -subj "/CN=kubernetes/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=k8s" -config ca.cnf -extensions v3_req openssl genrsa -out apiserver.key 3072 openssl req -new -key apiserver.key -out apiserver.csr -subj "/CN=kubernetes/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=k8s" -config api-server.cnf openssl x509 -req -in apiserver.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out apiserver.pem -days 10950 -extfile api-server.cnf -extensions v3_req openssl x509 -noout -text -in apiserver.pem kubelet 证书签发 /etc/ssl/k8s fn=52-6 openssl genrsa -out kubelet-$fn.key 3072 openssl req -new -key kubelet-$fn.key -out kubelet-$fn.csr -subj "/CN=admin/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=system:masters" -config client.cnf openssl x509 -req -in kubelet-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kubelet-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req fn=52-7 openssl genrsa -out kubelet-$fn.key 3072 openssl req -new -key kubelet-$fn.key -out kubelet-$fn.csr -subj "/CN=admin/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=system:masters" -config client.cnf openssl x509 -req -in kubelet-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kubelet-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req fn=52-8 openssl genrsa -out kubelet-$fn.key 3072 openssl req -new -key kubelet-$fn.key -out kubelet-$fn.csr -subj "/CN=admin/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=system:masters" -config client.cnf openssl x509 -req -in kubelet-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kubelet-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req kube-proxy 签发证书 /etc/ssl/k8s fn=52-6 openssl genrsa -out kube-proxy-$fn.key 3072 openssl req -new -key kube-proxy-$fn.key -out kube-proxy-$fn.csr -subj "/CN=system:kube-proxy/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=k8s" -config client.cnf openssl x509 -req -in kube-proxy-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kube-proxy-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req fn=52-7 openssl genrsa -out kube-proxy-$fn.key 3072 openssl req -new -key kube-proxy-$fn.key -out kube-proxy-$fn.csr -subj "/CN=system:kube-proxy/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=k8s" -config client.cnf openssl x509 -req -in kube-proxy-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kube-proxy-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req fn=52-8 openssl genrsa -out kube-proxy-$fn.key 3072 openssl req -new -key kube-proxy-$fn.key -out kube-proxy-$fn.csr -subj "/CN=system:kube-proxy/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=k8s" -config client.cnf openssl x509 -req -in kube-proxy-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kube-proxy-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req k8s ca apiserver kubelet 签发证书 标签:ast min ext etc extension pen sub day src 原文地址:https://www.cnblogs.com/S--S/p/11748659.html
文章标题:k8s ca apiserver kubelet 签发证书
文章链接:http://soscw.com/index.php/essay/87053.html