遙遙背影暖暖流星 2021-10-01 17:19
浏览 29
已结题

二进制部署k8s,在生成证书的时候报错

系统是centos 7
二进制部署k8s的时候,在系统最小化的机子上,生成证书的时时候报错

[root@master etcd-cert]# cfssl gencert -initca ca-csr.json | cfssljson -bare ca -
2021/10/01 16:32:01 [INFO] generating a new CA key and certificate from CSR
2021/10/01 16:32:01 [INFO] generate received request
2021/10/01 16:32:01 [INFO] received CSR
2021/10/01 16:32:01 [INFO] generating key: rsa-2048
2021/10/01 16:32:01 [INFO] encoded CSR
2021/10/01 16:32:01 [INFO] signed certificate with serial number 901726721497474484978362833954745738531503
段错误

后来换了一台机子,是有安装了发开者工具和可视化界面的,则生成证书可以成功

[root@node2 etcd-cert]# cfssl gencert -ca=ca.pem -ca-key=ca-key.pem -config=ca-config.json -profile=www server-csr.json | cfssljson -bare serve
2021/10/01 17:08:42 [INFO] generate received request
2021/10/01 17:08:42 [INFO] received CSR
2021/10/01 17:08:42 [INFO] generating key: rsa-2048
2021/10/01 17:08:42 [INFO] encoded CSR
2021/10/01 17:08:42 [INFO] signed certificate with serial number 155002876625188558567550739859568721790390435107
2021/10/01 17:08:42 [WARNING] This certificate lacks a "hosts" field. This makes it unsuitable for
websites. For more information see the Baseline Requirements for the Issuance and Management
of Publicly-Trusted Certificates, v.1.1.6, from the CA/Browser Forum (https://cabforum.org);
specifically, section 10.2.3 ("Information Requirements").
[root@node2 etcd-cert]#
[root@node2 etcd-cert]#
[root@node2 etcd-cert]#
[root@node2 etcd-cert]#
[root@node2 etcd-cert]# ls
ca-config.json  ca-csr.json  ca.pem     serve-key.pem  server-csr.json
ca.csr          ca-key.pem   serve.csr  serve.pem
[root@node2 etcd-cert]#

想知道最小化安装少了啥,导致生成证书失败

  • 写回答

0条回答 默认 最新

    报告相同问题?

    问题事件

    • 系统已结题 10月9日
    • 创建了问题 10月1日