@@ -49,6 +49,7 @@ if [ -z ${CONFIG} ]; then
49
49
echo " ERROR: the openssl configuration file is missing. option -f"
50
50
exit 1
51
51
fi
52
+ cat ${CONFIG}
52
53
if [ -z ${SSLDIR} ]; then
53
54
SSLDIR=" /etc/ssl/etcd"
54
55
fi
@@ -64,33 +65,33 @@ if [ -e "$SSLDIR/ca-key.pem" ]; then
64
65
# Reuse existing CA
65
66
cp $SSLDIR /{ca.pem,ca-key.pem} .
66
67
else
67
- openssl genrsa -out ca-key.pem {{certificates_key_size}} > /dev/null 2>&1
68
- openssl req -x509 -new -nodes -key ca-key.pem -days {{certificates_duration}} -out ca.pem -subj " /CN=etcd-ca" > /dev/null 2>&1
68
+ openssl genrsa -out ca-key.pem {{certificates_key_size}}
69
+ openssl req -x509 -new -nodes -key ca-key.pem -days {{certificates_duration}} -out ca.pem -subj " /CN=etcd-ca"
69
70
fi
70
71
71
72
# ETCD member
72
73
if [ -n " $MASTERS " ]; then
73
74
for host in $MASTERS ; do
74
75
cn=" ${host%% .* } "
75
76
# Member key
76
- openssl genrsa -out member-${host} -key.pem {{certificates_key_size}} > /dev/null 2>&1
77
- openssl req -new -key member-${host} -key.pem -out member-${host} .csr -subj " /CN=etcd-member-${cn} " -config ${CONFIG} > /dev/null 2>&1
78
- openssl x509 -req -in member-${host} .csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out member-${host} .pem -days {{certificates_duration}} -extensions ssl_client -extfile ${CONFIG} > /dev/null 2>&1
77
+ openssl genrsa -out member-${host} -key.pem {{certificates_key_size}}
78
+ openssl req -new -key member-${host} -key.pem -out member-${host} .csr -subj " /CN=etcd-member-${cn} " -config ${CONFIG}
79
+ openssl x509 -req -in member-${host} .csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out member-${host} .pem -days {{certificates_duration}} -extensions ssl_client -extfile ${CONFIG}
79
80
80
81
# Admin key
81
- openssl genrsa -out admin-${host} -key.pem {{certificates_key_size}} > /dev/null 2>&1
82
- openssl req -new -key admin-${host} -key.pem -out admin-${host} .csr -subj " /CN=etcd-admin-${cn} " > /dev/null 2>&1
83
- openssl x509 -req -in admin-${host} .csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out admin-${host} .pem -days {{certificates_duration}} -extensions ssl_client -extfile ${CONFIG} > /dev/null 2>&1
82
+ openssl genrsa -out admin-${host} -key.pem {{certificates_key_size}}
83
+ openssl req -new -key admin-${host} -key.pem -out admin-${host} .csr -subj " /CN=etcd-admin-${cn} "
84
+ openssl x509 -req -in admin-${host} .csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out admin-${host} .pem -days {{certificates_duration}} -extensions ssl_client -extfile ${CONFIG}
84
85
done
85
86
fi
86
87
87
88
# Node keys
88
89
if [ -n " $HOSTS " ]; then
89
90
for host in $HOSTS ; do
90
91
cn=" ${host%% .* } "
91
- openssl genrsa -out node-${host} -key.pem {{certificates_key_size}} > /dev/null 2>&1
92
- openssl req -new -key node-${host} -key.pem -out node-${host} .csr -subj " /CN=etcd-node-${cn} " > /dev/null 2>&1
93
- openssl x509 -req -in node-${host} .csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out node-${host} .pem -days {{certificates_duration}} -extensions ssl_client -extfile ${CONFIG} > /dev/null 2>&1
92
+ openssl genrsa -out node-${host} -key.pem {{certificates_key_size}}
93
+ openssl req -new -key node-${host} -key.pem -out node-${host} .csr -subj " /CN=etcd-node-${cn} "
94
+ openssl x509 -req -in node-${host} .csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out node-${host} .pem -days {{certificates_duration}} -extensions ssl_client -extfile ${CONFIG}
94
95
done
95
96
fi
96
97
0 commit comments