fix: ca-config.json by libinglong

pull/1186/head
jin.gjm 2022-09-17 21:52:48 +08:00
parent 272ede8ed6
commit 41c047b3f0
2 changed files with 24 additions and 26 deletions

View File

@ -27,27 +27,27 @@ kubernetes 系统各组件需要使用 TLS 证书对通信进行加密,使用
#### 创建 CA 配置文件 [ca-config.json.j2](../../roles/deploy/templates/ca-config.json.j2) #### 创建 CA 配置文件 [ca-config.json.j2](../../roles/deploy/templates/ca-config.json.j2)
``` bash ``` bash
{ {
"signing":{ "signing": {
"default":{ "default": {
"expiry":"{{ CERT_EXPIRY }}" "expiry": "{{ CERT_EXPIRY }}"
}, },
"profiles":{ "profiles": {
"kubernetes":{ "kubernetes": {
"usages":[ "usages": [
"signing", "signing",
"key encipherment", "key encipherment",
"server auth", "server auth",
"client auth" "client auth"
], ],
"expiry":"{{ CERT_EXPIRY }}" "expiry": "{{ CERT_EXPIRY }}"
}, },
"kcfg":{ "kcfg": {
"usages":[ "usages": [
"signing", "signing",
"key encipherment", "key encipherment",
"client auth" "client auth"
], ],
"expiry":"{{ CUSTOM_EXPIRY }}" "expiry": "{{ CUSTOM_EXPIRY }}"
} }
} }
} }

View File

@ -12,9 +12,7 @@
"client auth" "client auth"
], ],
"expiry": "{{ CERT_EXPIRY }}" "expiry": "{{ CERT_EXPIRY }}"
}
}, },
"profiles": {
"kcfg": { "kcfg": {
"usages": [ "usages": [
"signing", "signing",