#APISIX部署本次集群IP:192.168.1.41,192.168.1.42,192.168.1.43
#下载CFSSL软件
wget https://github.com/cloudflare/cfssl/releases/download/v1.6.3/cfssl_1.6.3_linux_amd64
wget https://github.com/cloudflare/cfssl/releases/download/v1.6.3/cfssl-certinfo_1.6.3_linux_amd64
wget https://github.com/cloudflare/cfssl/releases/download/v1.6.3/cfssljson_1.6.3_linux_amd64
#只需上传到第一个etcd1节点的/opt/CFSSL下
mv /opt/CFSSL/cfssl_1.6.3_linux_amd64 /usr/local/bin/cfssl
mv /opt/CFSSL/cfssl-certinfo_1.6.3_linux_amd64 /usr/local/bin/cfssl-certinfo
mv /opt/CFSSL/cfssljson_1.6.3_linux_amd64 /usr/local/bin/cfssljson
chmod u+x /usr/local/bin/cfssl
chmod u+x /usr/local/bin/cfssl-certinfo
chmod u+x /usr/local/bin/cfssljson
#三个节点全部创建目录
mkdir -p /data/etcd/{bin,ssl,data}
#在第一个节点进行配置证书后复制到其他节点即可
cd /data/etcd/ssl
cat > ca-config.json <<EOF
{
"signing": {
"default": {
"expiry": "262800h"
},
"profiles": {
"etcd": {
"expiry": "262800h",
"usages": [
"signing",
"key encipherment",
"server auth",
"client auth"
]
}
}
}
}
EOF
cat > ca-csr.json << EOF

最低0.47元/天 解锁文章
9919

被折叠的 条评论
为什么被折叠?



