證書下載官方地址:https://pkg.cfssl.orgnode
#下面三個安裝包,無需下載,以前百度雲中的壓縮包中都有
[root@linux-node1 ~]# cd /usr/local/src [root@linux-node1 src]# wget https://pkg.cfssl.org/R1.2/cfssl_linux-amd64 [root@linux-node1 src]# wget https://pkg.cfssl.org/R1.2/cfssljson_linux-amd64 [root@linux-node1 src]# wget https://pkg.cfssl.org/R1.2/cfssl-certinfo_linux-amd64 [root@linux-node1 src]# chmod +x cfssl* [root@linux-node1 src]# mv cfssl-certinfo_linux-amd64 /opt/kubernetes/bin/cfssl-certinfo [root@linux-node1 src]# mv cfssljson_linux-amd64 /opt/kubernetes/bin/cfssljson [root@linux-node1 src]# mv cfssl_linux-amd64 /opt/kubernetes/bin/cfssl 複製cfssl命令文件到k8s-node1和k8s-node2節點。若是實際中多個節點,就都須要同步複製。 [root@linux-node1 ~]# scp /opt/kubernetes/bin/cfssl* 192.168.56.12: /opt/kubernetes/bin [root@linux-node1 ~]# scp /opt/kubernetes/bin/cfssl* 192.168.56.13: /opt/kubernetes/bin
[root@linux-node1 ~]# cd /usr/local/src/ [root@linux-node1 src]# mkdir ssl && cd ssl [root@linux-node1 ssl]# pwd /usr/local/src/ssl
[root@linux-node1 ssl]# vim ca-config.json { "signing": { "default": { "expiry": "8760h" }, "profiles": { "kubernetes": { "usages": [ "signing", "key encipherment", "server auth", "client auth" ], "expiry": "8760h" } } } }
[root@linux-node1 ssl]# vim ca-csr.json { "CN": "kubernetes", "key": { "algo": "rsa", "size": 2048 }, "names": [ { "C": "CN", "ST": "BeiJing", "L": "BeiJing", "O": "k8s", "OU": "System" } ] }
[root@linux-node1 ssl]# cfssl gencert -initca ca-csr.json | cfssljson -bare ca 2018/05/30 20:57:27 [INFO] generating a new CA key and certificate from CSR 2018/05/30 20:57:27 [INFO] generate received request 2018/05/30 20:57:27 [INFO] received CSR 2018/05/30 20:57:27 [INFO] generating key: rsa-2048 2018/05/30 20:57:27 [INFO] encoded CSR 2018/05/30 20:57:27 [INFO] signed certificate with serial number 373140524131197437929619452877769287318483665014 [root@linux-node1 ssl]# ls -l total 20 -rw-r--r-- 1 root root 290 May 30 20:55 ca-config.json -rw-r--r-- 1 root root 1001 May 30 20:57 ca.csr -rw-r--r-- 1 root root 208 May 30 20:56 ca-csr.json -rw------- 1 root root 1675 May 30 20:57 ca-key.pem
[root@linux-node1 ssl]# cp ca.csr ca.pem ca-key.pem ca-config.json /opt/kubernetes/ssl SCP證書到k8s-node1和k8s-node2節點 [root@linux-node1 ssl]# scp ca.csr ca.pem ca-key.pem ca-config.json 192.168.56.12:/opt/kubernetes/ssl [root@linux-node1 ssl]# scp ca.csr ca.pem ca-key.pem ca-config.json 192.168.56.13:/opt/kubernetes/ssl