Fix proxy auth tls

This commit is contained in:
Tom Alexander 2026-01-11 13:03:20 -05:00 committed by Tom Alexander
parent 3c9901709f
commit 42c433eb00
Signed by: talexander
GPG Key ID: 36C99E8B3C39D85F

View File

@ -11,7 +11,10 @@ keyUsage = cRLSign, keyCertSign
C = US C = US
ST = Washington ST = Washington
L = Seattle L = Seattle
CN = CA CN = Kubernetes
O = Kubernetes
OU = CA
[controller0-proxy] [controller0-proxy]
distinguished_name = controller0_distinguished_name distinguished_name = controller0_distinguished_name
@ -23,7 +26,7 @@ basicConstraints = CA:FALSE
extendedKeyUsage = clientAuth, serverAuth extendedKeyUsage = clientAuth, serverAuth
keyUsage = critical, digitalSignature, keyEncipherment keyUsage = critical, digitalSignature, keyEncipherment
nsCertType = client nsCertType = client
nsComment = "controller0 Certificate" nsComment = "controller0-proxy Certificate"
subjectAltName = @controller0_alt_names subjectAltName = @controller0_alt_names
subjectKeyIdentifier = hash subjectKeyIdentifier = hash
@ -36,8 +39,8 @@ L = Seattle
[controller0_alt_names] [controller0_alt_names]
IP.0 = 127.0.0.1 IP.0 = 127.0.0.1
IP.4 = 10.215.1.221 IP.1 = 10.215.1.221
IP.5 = 2620:11f:7001:7:ffff:ffff:0ad7:01dd IP.2 = 2620:11f:7001:7:ffff:ffff:0ad7:01dd
DNS.0 = controller0 DNS.0 = controller0
[controller1-proxy] [controller1-proxy]
@ -50,7 +53,7 @@ basicConstraints = CA:FALSE
extendedKeyUsage = clientAuth, serverAuth extendedKeyUsage = clientAuth, serverAuth
keyUsage = critical, digitalSignature, keyEncipherment keyUsage = critical, digitalSignature, keyEncipherment
nsCertType = client nsCertType = client
nsComment = "controller1 Certificate" nsComment = "controller1-proxy Certificate"
subjectAltName = @controller1_alt_names subjectAltName = @controller1_alt_names
subjectKeyIdentifier = hash subjectKeyIdentifier = hash
@ -77,7 +80,7 @@ basicConstraints = CA:FALSE
extendedKeyUsage = clientAuth, serverAuth extendedKeyUsage = clientAuth, serverAuth
keyUsage = critical, digitalSignature, keyEncipherment keyUsage = critical, digitalSignature, keyEncipherment
nsCertType = client nsCertType = client
nsComment = "controller2 Certificate" nsComment = "controller2-proxy Certificate"
subjectAltName = @controller2_alt_names subjectAltName = @controller2_alt_names
subjectKeyIdentifier = hash subjectKeyIdentifier = hash
@ -90,6 +93,6 @@ L = Seattle
[controller2_alt_names] [controller2_alt_names]
IP.0 = 127.0.0.1 IP.0 = 127.0.0.1
IP.6 = 10.215.1.223 IP.1 = 10.215.1.223
IP.7 = 2620:11f:7001:7:ffff:ffff:0ad7:01df IP.2 = 2620:11f:7001:7:ffff:ffff:0ad7:01df
DNS.0 = controller2 DNS.0 = controller2