系统是centos 7
二进制部署k8s的时候,在系统最小化的机子上,生成证书的时时候报错
[root@master etcd-cert]# cfssl gencert -initca ca-csr.json | cfssljson -bare ca -
2021/10/01 16:32:01 [INFO] generating a new CA key and certificate from CSR
2021/10/01 16:32:01 [INFO] generate received request
2021/10/01 16:32:01 [INFO] received CSR
2021/10/01 16:32:01 [INFO] generating key: rsa-2048
2021/10/01 16:32:01 [INFO] encoded CSR
2021/10/01 16:32:01 [INFO] signed certificate with serial number 901726721497474484978362833954745738531503
段错误
后来换了一台机子,是有安装了发开者工具和可视化界面的,则生成证书可以成功
[root@node2 etcd-cert]# cfssl gencert -ca=ca.pem -ca-key=ca-key.pem -config=ca-config.json -profile=www server-csr.json | cfssljson -bare serve
2021/10/01 17:08:42 [INFO] generate received request
2021/10/01 17:08:42 [INFO] received CSR
2021/10/01 17:08:42 [INFO] generating key: rsa-2048
2021/10/01 17:08:42 [INFO] encoded CSR
2021/10/01 17:08:42 [INFO] signed certificate with serial number 155002876625188558567550739859568721790390435107
2021/10/01 17:08:42 [WARNING] This certificate lacks a "hosts" field. This makes it unsuitable for
websites. For more information see the Baseline Requirements for the Issuance and Management
of Publicly-Trusted Certificates, v.1.1.6, from the CA/Browser Forum (https://cabforum.org);
specifically, section 10.2.3 ("Information Requirements").
[root@node2 etcd-cert]#
[root@node2 etcd-cert]#
[root@node2 etcd-cert]#
[root@node2 etcd-cert]#
[root@node2 etcd-cert]# ls
ca-config.json ca-csr.json ca.pem serve-key.pem server-csr.json
ca.csr ca-key.pem serve.csr serve.pem
[root@node2 etcd-cert]#
想知道最小化安装少了啥,导致生成证书失败