echo/scripts/gen-certs.sh
Jean 0af7f10c3d
Add mutual-TLS to the gossip link
Optional [gossip.tls] wraps the peer link in TLS: each node presents a
certificate and requires the peer to present one signed by the configured
CA. scripts/gen-certs.sh builds a CA and node certs.
2026-07-12 07:31:16 +00:00

23 lines
849 B
Bash
Executable file

#!/usr/bin/env bash
# Generate a CA and one node certificate for the gossip mutual-TLS link.
# Point every node's [gossip.tls] at ca.crt, and give each its own node cert/key.
# Usage: scripts/gen-certs.sh [out-dir] [node-name]
set -euo pipefail
DIR="${1:-certs}"
NAME="${2:-fedserv}"
mkdir -p "$DIR"
cd "$DIR"
if [ ! -f ca.crt ]; then
openssl req -x509 -newkey ec -pkeyopt ec_paramgen_curve:P-256 -nodes \
-keyout ca.key -out ca.crt -days 3650 -subj "/CN=fedserv-ca"
fi
openssl req -newkey ec -pkeyopt ec_paramgen_curve:P-256 -nodes \
-keyout "$NAME.key" -out "$NAME.csr" -subj "/CN=$NAME"
openssl x509 -req -in "$NAME.csr" -CA ca.crt -CAkey ca.key -CAcreateserial \
-out "$NAME.crt" -days 3650 \
-extfile <(printf "subjectAltName=DNS:%s" "$NAME")
rm -f "$NAME.csr" ca.srl
echo "wrote $DIR/{ca.crt, $NAME.crt, $NAME.key}"