Add mutual-TLS to the gossip link
Optional [gossip.tls] wraps the peer link in TLS: each node presents a certificate and requires the peer to present one signed by the configured CA. scripts/gen-certs.sh builds a CA and node certs.
This commit is contained in:
parent
cc0265548f
commit
0af7f10c3d
5 changed files with 434 additions and 19 deletions
23
scripts/gen-certs.sh
Executable file
23
scripts/gen-certs.sh
Executable file
|
|
@ -0,0 +1,23 @@
|
|||
#!/usr/bin/env bash
|
||||
# Generate a CA and one node certificate for the gossip mutual-TLS link.
|
||||
# Point every node's [gossip.tls] at ca.crt, and give each its own node cert/key.
|
||||
# Usage: scripts/gen-certs.sh [out-dir] [node-name]
|
||||
set -euo pipefail
|
||||
DIR="${1:-certs}"
|
||||
NAME="${2:-fedserv}"
|
||||
mkdir -p "$DIR"
|
||||
cd "$DIR"
|
||||
|
||||
if [ ! -f ca.crt ]; then
|
||||
openssl req -x509 -newkey ec -pkeyopt ec_paramgen_curve:P-256 -nodes \
|
||||
-keyout ca.key -out ca.crt -days 3650 -subj "/CN=fedserv-ca"
|
||||
fi
|
||||
|
||||
openssl req -newkey ec -pkeyopt ec_paramgen_curve:P-256 -nodes \
|
||||
-keyout "$NAME.key" -out "$NAME.csr" -subj "/CN=$NAME"
|
||||
openssl x509 -req -in "$NAME.csr" -CA ca.crt -CAkey ca.key -CAcreateserial \
|
||||
-out "$NAME.crt" -days 3650 \
|
||||
-extfile <(printf "subjectAltName=DNS:%s" "$NAME")
|
||||
rm -f "$NAME.csr" ca.srl
|
||||
|
||||
echo "wrote $DIR/{ca.crt, $NAME.crt, $NAME.key}"
|
||||
Loading…
Add table
Add a link
Reference in a new issue