mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-28 05:59:03 +00:00
#384 Clarify which CA certs are needed
This commit is contained in:
@@ -25,9 +25,9 @@ If you want to replace the certificate, you can delete the `tls-rancher-ingress`
|
|||||||
|
|
||||||
## Using a Private CA Signed Certificate
|
## Using a Private CA Signed Certificate
|
||||||
|
|
||||||
If you are using a private CA, Rancher requires a copy of the CA certificate which is used by the Rancher Agent to validate the connection to the server.
|
If you are using a private CA, Rancher requires a copy of the private CA's root certificate or certificate chain, which the Rancher Agent uses to validate the connection to the server.
|
||||||
|
|
||||||
Copy the CA certificate into a file named `cacerts.pem` and use `kubectl` to create the `tls-ca` secret in the `cattle-system` namespace.
|
Create a file named `cacerts.pem` that only contains the root CA certificate or certificate chain from your private CA, and use `kubectl` to create the `tls-ca` secret in the `cattle-system` namespace.
|
||||||
|
|
||||||
```
|
```
|
||||||
kubectl -n cattle-system create secret generic tls-ca \
|
kubectl -n cattle-system create secret generic tls-ca \
|
||||||
|
|||||||
+2
-2
@@ -19,9 +19,9 @@ kubectl -n cattle-system create secret tls tls-rancher-ingress \
|
|||||||
|
|
||||||
### Using a Private CA Signed Certificate
|
### Using a Private CA Signed Certificate
|
||||||
|
|
||||||
If you are using a private CA, Rancher requires a copy of the CA certificate which is used by the Rancher Agent to validate the connection to the server.
|
If you are using a private CA, Rancher requires a copy of the private CA's root certificate or certificate chain, which the Rancher Agent uses to validate the connection to the server.
|
||||||
|
|
||||||
Copy the CA certificate into a file named `cacerts.pem` and use `kubectl` to create the `tls-ca` secret in the `cattle-system` namespace.
|
Create a file named `cacerts.pem` that only contains the root CA certificate or certificate chain from your private CA, and use `kubectl` to create the `tls-ca` secret in the `cattle-system` namespace.
|
||||||
|
|
||||||
>**Important:** Make sure the file is called `cacerts.pem` as Rancher uses that filename to configure the CA certificate.
|
>**Important:** Make sure the file is called `cacerts.pem` as Rancher uses that filename to configure the CA certificate.
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -21,9 +21,9 @@ kubectl -n cattle-system create secret tls tls-rancher-ingress \
|
|||||||
|
|
||||||
## Using a Private CA Signed Certificate
|
## Using a Private CA Signed Certificate
|
||||||
|
|
||||||
If you are using a private CA, Rancher requires a copy of the CA certificate which is used by the Rancher Agent to validate the connection to the server.
|
If you are using a private CA, Rancher requires a copy of the private CA's root certificate or certificate chain, which the Rancher Agent uses to validate the connection to the server.
|
||||||
|
|
||||||
Copy the CA certificate into a file named `cacerts.pem` and use `kubectl` to create the `tls-ca` secret in the `cattle-system` namespace.
|
Create a file named `cacerts.pem` that only contains the root CA certificate or certificate chain from your private CA, and use `kubectl` to create the `tls-ca` secret in the `cattle-system` namespace.
|
||||||
|
|
||||||
```
|
```
|
||||||
kubectl -n cattle-system create secret generic tls-ca \
|
kubectl -n cattle-system create secret generic tls-ca \
|
||||||
|
|||||||
+2
-2
@@ -21,9 +21,9 @@ kubectl -n cattle-system create secret tls tls-rancher-ingress \
|
|||||||
|
|
||||||
## Using a Private CA Signed Certificate
|
## Using a Private CA Signed Certificate
|
||||||
|
|
||||||
If you are using a private CA, Rancher requires a copy of the CA certificate which is used by the Rancher Agent to validate the connection to the server.
|
If you are using a private CA, Rancher requires a copy of the private CA's root certificate or certificate chain, which the Rancher Agent uses to validate the connection to the server.
|
||||||
|
|
||||||
Copy the CA certificate into a file named `cacerts.pem` and use `kubectl` to create the `tls-ca` secret in the `cattle-system` namespace.
|
Create a file named `cacerts.pem` that only contains the root CA certificate or certificate chain from your private CA, and use `kubectl` to create the `tls-ca` secret in the `cattle-system` namespace.
|
||||||
|
|
||||||
```
|
```
|
||||||
kubectl -n cattle-system create secret generic tls-ca \
|
kubectl -n cattle-system create secret generic tls-ca \
|
||||||
|
|||||||
+2
-2
@@ -25,9 +25,9 @@ If you want to replace the certificate, you can delete the `tls-rancher-ingress`
|
|||||||
|
|
||||||
## Using a Private CA Signed Certificate
|
## Using a Private CA Signed Certificate
|
||||||
|
|
||||||
If you are using a private CA, Rancher requires a copy of the CA certificate which is used by the Rancher Agent to validate the connection to the server.
|
If you are using a private CA, Rancher requires a copy of the private CA's root certificate or certificate chain, which the Rancher Agent uses to validate the connection to the server.
|
||||||
|
|
||||||
Copy the CA certificate into a file named `cacerts.pem` and use `kubectl` to create the `tls-ca` secret in the `cattle-system` namespace.
|
Create a file named `cacerts.pem` that only contains the root CA certificate or certificate chain from your private CA, and use `kubectl` to create the `tls-ca` secret in the `cattle-system` namespace.
|
||||||
|
|
||||||
```
|
```
|
||||||
kubectl -n cattle-system create secret generic tls-ca \
|
kubectl -n cattle-system create secret generic tls-ca \
|
||||||
|
|||||||
Reference in New Issue
Block a user