Commit 580f413 1 parent a9fc0d0 commit 580f413 Copy full SHA for 580f413
File tree 1 file changed +23
-25
lines changed
1 file changed +23
-25
lines changed Original file line number Diff line number Diff line change @@ -27,32 +27,30 @@ kubernetes 系统各组件需要使用 TLS 证书对通信进行加密,使用
27
27
#### 创建 CA 配置文件 [ ca-config.json.j2] ( ../../roles/deploy/templates/ca-config.json.j2 )
28
28
``` bash
29
29
{
30
- " signing" : {
31
- " default" : {
32
- " expiry" : " {{ CERT_EXPIRY }}"
33
- },
34
- " profiles" : {
35
- " kubernetes" : {
36
- " usages" : [
37
- " signing" ,
38
- " key encipherment" ,
39
- " server auth" ,
40
- " client auth"
41
- ],
42
- " expiry" : " {{ CERT_EXPIRY }}"
43
- }
44
- },
45
- " profiles" : {
46
- " kcfg" : {
47
- " usages" : [
48
- " signing" ,
49
- " key encipherment" ,
50
- " client auth"
51
- ],
52
- " expiry" : " {{ CUSTOM_EXPIRY }}"
53
- }
30
+ " signing" :{
31
+ " default" :{
32
+ " expiry" :" {{ CERT_EXPIRY }}"
33
+ },
34
+ " profiles" :{
35
+ " kubernetes" :{
36
+ " usages" :[
37
+ " signing" ,
38
+ " key encipherment" ,
39
+ " server auth" ,
40
+ " client auth"
41
+ ],
42
+ " expiry" :" {{ CERT_EXPIRY }}"
43
+ },
44
+ " kcfg" :{
45
+ " usages" :[
46
+ " signing" ,
47
+ " key encipherment" ,
48
+ " client auth"
49
+ ],
50
+ " expiry" :" {{ CUSTOM_EXPIRY }}"
51
+ }
52
+ }
54
53
}
55
- }
56
54
}
57
55
```
58
56
+ ` signing ` :表示该证书可用于签名其它证书;生成的 ca.pem 证书中 ` CA=TRUE ` ;
You can’t perform that action at this time.
0 commit comments