首页 新闻 会员 周边

如何刷新 Kubernetes 集群的 CA 证书

0
悬赏园豆:50 [待解决问题]

用下面的命令只能刷新非 CA 的证书

kubeadm certs renew all

刷新之后的结果

CERTIFICATE                EXPIRES                  RESIDUAL TIME   CERTIFICATE AUTHORITY   EXTERNALLY MANAGED
admin.conf                 Mar 04, 2022 09:06 UTC   364d                                    no      
apiserver                  Mar 04, 2022 09:06 UTC   364d            ca                      no      
apiserver-etcd-client      Mar 04, 2022 09:06 UTC   364d            etcd-ca                 no      
apiserver-kubelet-client   Mar 04, 2022 09:06 UTC   364d            ca                      no      
controller-manager.conf    Mar 04, 2022 09:06 UTC   364d                                    no      
etcd-healthcheck-client    Mar 04, 2022 09:06 UTC   364d            etcd-ca                 no      
etcd-peer                  Mar 04, 2022 09:06 UTC   364d            etcd-ca                 no      
etcd-server                Mar 04, 2022 09:06 UTC   364d            etcd-ca                 no      
front-proxy-client         Mar 04, 2022 09:06 UTC   364d            front-proxy-ca          no      
scheduler.conf             Mar 04, 2022 09:06 UTC   364d                                    no      

CERTIFICATE AUTHORITY   EXPIRES                  RESIDUAL TIME   EXTERNALLY MANAGED
ca                      Jan 06, 2030 08:51 UTC   8y              no      
etcd-ca                 Jan 06, 2030 08:51 UTC   8y              no      
front-proxy-ca          Jan 18, 2031 09:09 UTC   9y              no

请问如何刷新 CERTIFICATE AUTHORITY 部分的证书?

k8s
dudu的主页 dudu | 高人七级 | 园豆:31007
提问于:2021-03-04 17:48
< >
分享
所有回答(1)
0

网上ca证书编译源码也无效
https://blog.csdn.net/netgc/article/details/106456770?utm_medium=distribute.pc_feed_404.none-task-blog-2defaultBlogCommendFromBaidudefault-1.control404&depth_1-utm_source=distribute.pc_feed_404.none-task-blog-2defaultBlogCommendFromBaidudefault-1.control40

軒轅劍 | 园豆:64 (初学一级) | 2021-12-20 17:39
清除回答草稿
   您需要登录以后才能回答,未注册用户请先注册