⎈ k8s knowledge compiler

Generate Certificates Manually [page]deterministic

taskssecurity

When using client certificate authentication, you can generate certificates manually through [`easyrsa`](https://github.com/OpenVPN/easy-rsa), [`openssl`](https://github.com/openssl/openssl) or [`cfssl`](https://github.com/cloudflare/cfssl).

### easyrsa

easyrsa can manually generate certificates for your cluster.

1. Download, unpack, and initialize the patched version of `easyrsa3`.

```shell curl -LO https://dl.k8s.io/easy-rsa/easy-rsa.tar.gz tar xzf easy-rsa.tar.gz cd easy-rsa-master/easyrsa3 ./easyrsa init-pki ``` 1. Generate a new certificate authority (CA). `--batch` sets automatic mode; `--req-cn` specifies the Common Name (CN) for the CA's new root certificate.

```shell ./easyrsa --batch "--req-cn=${MASTER_IP}@`date +%s`" build-ca nopass ```

1. Generate server certificate and key.

The argument `--subject-alt-name` sets the possible IPs and DNS names the API server will be accessed with. The `MASTER_CLUSTER_IP` is usually the first IP from the service CIDR that is specified as the `--service-cluster-ip-range` argument for both the API server and the controller manager component. The argument `--days` is used to set the number of days after which the certificate expires. The sample below also assumes that you are using `cluster.local` as the default DNS domain name.

```shell ./easyrsa --subject-alt-name="IP:${MASTER_IP},"\ "IP:${MASTER_CLUSTER_IP},"\ "DNS:kubernetes,"\ "DNS:kubernetes.default,"\ "DNS:kubernetes.default.svc,"\ "DNS:kubernetes.default.svc.cluster,"\ "DNS:kubernetes.default.svc.cluster.local" \ --days=10000 \ build-server-full server nopass ```

1. Copy `pki/ca.crt`, `pki/issued/server.crt`, and `pki/private/server.key` to your directory.

1. Fill in and add the following parameters into the API server start parameters:

```shell --client-ca-file=/yourdirectory/ca.crt --tls-cert-file=/yourdirectory/server.crt --tls-private-key-file=/yourdirectory/server.key ```

### openssl

openssl can manually generate certificates for your cluster.

1. Generate a ca.key with 2048bit:

```shell openssl genrsa -out ca.key 2048 ```

1. According to the ca.key generate a ca.crt (use `-days` to set the certificate effective time):

```shell openssl req -x509 -new -noenc -key ca.key -subj "/CN=${MASTER_IP}" -days 10000 -out ca.crt ```

1. Generate a server.key with 2048bit:

```shell openssl genrsa -out server.key 2048 ```

1. Create a config file for generating a Certificate Signing Request (CSR).

Be sure to substitute the values marked with angle brackets (e.g. `<MASTER_IP>`) with real values before saving this to a file (e.g. `csr.conf`). Note that the value for `MASTER_CLUSTER_IP` is the service cluster IP for the API server as described in previous subsection. The sample below also assumes that you are using `cluster.local` as the default DNS domain name.

```ini [ req ] default_bits = 2048 prompt = no default_md = sha256 req_extensions = req_ext distinguished_name = dn

[ dn ] C = <country> ST = <state> L = <city> O = <organization> OU = <organization unit> CN = <MASTER_IP>

[ req_ext ] subjectAltName = @alt_names

[ alt_names ] DNS.1 = kubernetes DNS.2 = kubernetes.default DNS.3 = kubernetes.default.svc DNS.4 = kubernetes.default.svc.cluster DNS.5 = kubernetes.default.svc.cluster.local IP.1 = <MASTER_IP> IP.2 = <MASTER_CLUSTER_IP>

[ v3_ext ] authorityKeyIdentifier=keyid,issuer:always basicConstraints=CA:FALSE keyUsage=keyEncipherment,dataEncipherment extendedKeyUsage=serverAuth,clientAuth subjectAltName=@alt_names ```

1. Generate the certificate signing request based on the config file:

```shell openssl req -new -key server.key -out server.csr -config csr.conf ```

1. Generate the server certificate using the ca.key, ca.crt and server.csr:

```shell o …(trimmed)

Sources

tasks/administer-cluster/certificates.md · docGenerate Certificates Manually

Related (5)

part_of Distributing Self-Signed CA Certificatedescribes conf=1
part_of Certificates APIdescribes conf=1
part_of easyrsadescribes conf=1
part_of openssldescribes conf=1
part_of cfssldescribes conf=1

← all Docs