diff --git a/layouts/shortcodes/ssl_faq_single.html b/layouts/shortcodes/ssl_faq_single.html index aa3d2acefae..71f02c6b4d0 100644 --- a/layouts/shortcodes/ssl_faq_single.html +++ b/layouts/shortcodes/ssl_faq_single.html @@ -17,6 +17,42 @@ VWQqljhfacYPgp8KJUJENQ9h5hZ2nSCrI+W00Jcw4QcEdCI8HL5wmg== -----END CERTIFICATE----- +

PEM Certificate Key Example:

+ +
+-----BEGIN RSA PRIVATE KEY-----
+MIIGVDCCBDygAwIBAgIJAMiIrEm29kRLMA0GCSqGSIb3DQEBCwUAMHkxCzAJBgNV
+... more lines
+VWQqljhfacYPgp8KJUJENQ9h5hZ2nSCrI+W00Jcw4QcEdCI8HL5wmg==
+-----END RSA PRIVATE KEY-----
+
+ +

If your key looks like the example below, see How Can I Convert My Certificate Key From PKCS8 to PKCS1?

+ +

+-----BEGIN PRIVATE KEY-----
+MIIGVDCCBDygAwIBAgIJAMiIrEm29kRLMA0GCSqGSIb3DQEBCwUAMHkxCzAJBgNV
+... more lines
+VWQqljhfacYPgp8KJUJENQ9h5hZ2nSCrI+W00Jcw4QcEdCI8HL5wmg==
+-----END PRIVATE KEY-----
+
+ +

How Can I Convert My Certificate Key From PKCS8 to PKCS1?

+ +

If you are using a PKCS8 certificate key file, Rancher will log the following line:

+ +
+ListenConfigController cli-config [listener] failed with : failed to read private key: asn1: structure error: tags don't match (2 vs {class:0 tag:16 length:13 isCompound:true})
+
+ +

To make this work, you will need to convert the key from PKCS8 to PKCS1 using the command below:

+ +
+openssl rsa -in key.pem -out convertedkey.pem
+
+ +

You can now use convertedkey.pem as certificate key file for Rancher.

+

What is the Order of Certificates if I Want to Add My Intermediate(s)?

The order of adding certificates is as follows: