码迷,mamicode.com
首页 > Windows程序 > 详细

k8s ca apiserver kubelet 签发证书

时间:2019-10-27 20:45:44      阅读:154      评论:0      收藏:0      [点我收藏+]

标签:ast   min   ext   etc   extension   pen   sub   day   src   

3节点

  192.168.52.6  master

  192.168.52.7  node1

  192.168.52.8  node2

  

  /etc/ssl/k8s

    openssl genrsa -out ca.key 3072

    解压签发证书所需文件 百度网盘提供  https://pan.baidu.com/s/1K_A6T8SwuinzQiOosCV6QA

    openssl req -x509 -new -key ca.key -days 10950 -out ca.pem -subj "/CN=kubernetes/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=k8s" -config ca.cnf -extensions v3_req

    openssl genrsa -out apiserver.key 3072

      技术图片

    openssl req -new -key apiserver.key -out apiserver.csr -subj "/CN=kubernetes/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=k8s" -config api-server.cnf

    openssl x509 -req -in apiserver.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out apiserver.pem -days 10950 -extfile api-server.cnf -extensions v3_req

    openssl x509 -noout -text -in apiserver.pem

 

 

    kubelet 证书签发

      /etc/ssl/k8s

技术图片

 

     fn=52-6

     openssl genrsa -out kubelet-$fn.key 3072

     openssl req -new -key kubelet-$fn.key -out kubelet-$fn.csr -subj "/CN=admin/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=system:masters" -config client.cnf

     openssl x509 -req -in kubelet-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kubelet-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req

        技术图片

 

       fn=52-7

       openssl genrsa -out kubelet-$fn.key 3072

       openssl req -new -key kubelet-$fn.key -out kubelet-$fn.csr -subj "/CN=admin/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=system:masters" -config client.cnf

       openssl x509 -req -in kubelet-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kubelet-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req

 

       fn=52-8

       openssl genrsa -out kubelet-$fn.key 3072

       openssl req -new -key kubelet-$fn.key -out kubelet-$fn.csr -subj "/CN=admin/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=system:masters" -config client.cnf

       openssl x509 -req -in kubelet-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kubelet-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req

 

 

 

    kube-proxy 签发证书

      /etc/ssl/k8s

      技术图片

 

 

 

        fn=52-6

        openssl genrsa -out kube-proxy-$fn.key 3072

        openssl req -new -key kube-proxy-$fn.key -out kube-proxy-$fn.csr -subj "/CN=system:kube-proxy/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=k8s" -config client.cnf

        openssl x509 -req -in kube-proxy-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kube-proxy-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req

         

        fn=52-7

        openssl genrsa -out kube-proxy-$fn.key 3072

        openssl req -new -key kube-proxy-$fn.key -out kube-proxy-$fn.csr -subj "/CN=system:kube-proxy/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=k8s" -config client.cnf

        openssl x509 -req -in kube-proxy-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kube-proxy-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req

 

        fn=52-8

        openssl genrsa -out kube-proxy-$fn.key 3072

        openssl req -new -key kube-proxy-$fn.key -out kube-proxy-$fn.csr -subj "/CN=system:kube-proxy/OU=System/C=CN/ST=Shanghai/L=Shanghai/O=k8s" -config client.cnf

        openssl x509 -req -in kube-proxy-$fn.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out kube-proxy-$fn.pem -days 10950 -extfile client.cnf -extensions v3_req

k8s ca apiserver kubelet 签发证书

标签:ast   min   ext   etc   extension   pen   sub   day   src   

原文地址:https://www.cnblogs.com/S--S/p/11748659.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!