Generate Certificates Manually

easyrsa can manually generate certificates for your cluster.

  1. Download, unpack, and initialize the patched version of .

  2. Generate a new certificate authority (CA). --batch sets automatic mode; --req-cn specifies the Common Name (CN) for the CA’s new root certificate.

    1. ./easyrsa --batch "--req-cn=${MASTER_IP}@`date +%s`" build-ca nopass
  3. Generate server certificate and key.

    The argument --subject-alt-name sets the possible IPs and DNS names the API server will be accessed with. The MASTER_CLUSTER_IP is usually the first IP from the service CIDR that is specified as the --service-cluster-ip-range argument for both the API server and the controller manager component. The argument --days is used to set the number of days after which the certificate expires. The sample below also assumes that you are using cluster.local as the default DNS domain name.

    1. ./easyrsa --subject-alt-name="IP:${MASTER_IP},"\
    2. "IP:${MASTER_CLUSTER_IP},"\
    3. "DNS:kubernetes,"\
    4. "DNS:kubernetes.default,"\
    5. "DNS:kubernetes.default.svc,"\
    6. "DNS:kubernetes.default.svc.cluster,"\
    7. "DNS:kubernetes.default.svc.cluster.local" \
    8. --days=10000 \
    9. build-server-full server nopass
  4. Copy pki/ca.crt, pki/issued/server.crt, and pki/private/server.key to your directory.

  5. Fill in and add the following parameters into the API server start parameters:

    1. --client-ca-file=/yourdirectory/ca.crt
    2. --tls-cert-file=/yourdirectory/server.crt
    3. --tls-private-key-file=/yourdirectory/server.key

openssl can manually generate certificates for your cluster.

  1. Generate a ca.key with 2048bit:

    1. openssl genrsa -out ca.key 2048
    1. openssl req -x509 -new -nodes -key ca.key -subj "/CN=${MASTER_IP}" -days 10000 -out ca.crt
  2. Generate a server.key with 2048bit:

    1. openssl genrsa -out server.key 2048
  3. Create a config file for generating a Certificate Signing Request (CSR).

    Be sure to substitute the values marked with angle brackets (e.g. <MASTER_IP>) with real values before saving this to a file (e.g. csr.conf). Note that the value for MASTER_CLUSTER_IP is the service cluster IP for the API server as described in previous subsection. The sample below also assumes that you are using cluster.local as the default DNS domain name.

  4. Generate the certificate signing request based on the config file:

    1. openssl req -new -key server.key -out server.csr -config csr.conf
  5. Generate the server certificate using the ca.key, ca.crt and server.csr:

    1. openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
  6. View the certificate signing request:

    1. openssl req -noout -text -in ./server.csr
  7. View the certificate:

    1. openssl x509 -noout -text -in ./server.crt

Finally, add the same parameters into the API server start parameters.

cfssl is another tool for certificate generation.

  1. Note that you may need to adapt the sample commands based on the hardware architecture and cfssl version you are using.

    1. curl -L https://github.com/cloudflare/cfssl/releases/download/v1.5.0/cfssl_1.5.0_linux_amd64 -o cfssl
    2. chmod +x cfssl
    3. curl -L https://github.com/cloudflare/cfssl/releases/download/v1.5.0/cfssljson_1.5.0_linux_amd64 -o cfssljson
    4. chmod +x cfssljson
    5. curl -L https://github.com/cloudflare/cfssl/releases/download/v1.5.0/cfssl-certinfo_1.5.0_linux_amd64 -o cfssl-certinfo
    6. chmod +x cfssl-certinfo
  2. Create a directory to hold the artifacts and initialize cfssl:

    1. mkdir cert
    2. cd cert
    3. ../cfssl print-defaults config > config.json
    4. ../cfssl print-defaults csr > csr.json
  3. Create a JSON config file for generating the CA file, for example, ca-config.json:

  4. Create a JSON config file for CA certificate signing request (CSR), for example, ca-csr.json. Be sure to replace the values marked with angle brackets with real values you want to use.

    1. {
    2. "CN": "kubernetes",
    3. "key": {
    4. "algo": "rsa",
    5. "size": 2048
    6. },
    7. "names":[{
    8. "C": "<country>",
    9. "ST": "<state>",
    10. "L": "<city>",
    11. "O": "<organization>",
    12. "OU": "<organization unit>"
    13. }]
    14. }
  5. Generate CA key (ca-key.pem) and certificate (ca.pem):

    1. Create a JSON config file for generating keys and certificates for the API server, for example, server-csr.json. Be sure to replace the values in angle brackets with real values you want to use. The <MASTER_CLUSTER_IP> is the service cluster IP for the API server as described in previous subsection. The sample below also assumes that you are using cluster.local as the default DNS domain name.

      1. "CN": "kubernetes",
      2. "hosts": [
      3. "127.0.0.1",
      4. "<MASTER_IP>",
      5. "<MASTER_CLUSTER_IP>",
      6. "kubernetes",
      7. "kubernetes.default",
      8. "kubernetes.default.svc",
      9. "kubernetes.default.svc.cluster",
      10. "kubernetes.default.svc.cluster.local"
      11. ],
      12. "key": {
      13. "algo": "rsa",
      14. "size": 2048
      15. },
      16. "names": [{
      17. "C": "<country>",
      18. "ST": "<state>",
      19. "L": "<city>",
      20. "O": "<organization>",
      21. "OU": "<organization unit>"
      22. }]
      23. }
    2. Generate the key and certificate for the API server, which are by default saved into file server-key.pem and server.pem respectively:

      1. ../cfssl gencert -ca=ca.pem -ca-key=ca-key.pem \
      2. --config=ca-config.json -profile=kubernetes \
      3. server-csr.json | ../cfssljson -bare server

    A client node may refuse to recognize a self-signed CA certificate as valid. For a non-production deployment, or for a deployment that runs behind a company firewall, you can distribute a self-signed CA certificate to all clients and refresh the local list for valid certificates.

    On each client, perform the following operations:

    1. sudo cp ca.crt /usr/local/share/ca-certificates/kubernetes.crt
    2. sudo update-ca-certificates
    1. Updating certificates in /etc/ssl/certs...
    2. 1 added, 0 removed; done.
    3. Running hooks in /etc/ca-certificates/update.d....

    Certificates API