2016-11-09 10:44:41 +00:00
|
|
|
#!/bin/bash
|
|
|
|
|
|
|
|
# Author: Smana smainklh@gmail.com
|
|
|
|
#
|
|
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
# you may not use this file except in compliance with the License.
|
|
|
|
# You may obtain a copy of the License at
|
|
|
|
#
|
|
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
#
|
|
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
# See the License for the specific language governing permissions and
|
|
|
|
# limitations under the License.
|
|
|
|
|
|
|
|
set -o errexit
|
|
|
|
set -o pipefail
|
|
|
|
usage()
|
|
|
|
{
|
|
|
|
cat << EOF
|
|
|
|
Create self signed certificates
|
|
|
|
|
|
|
|
Usage : $(basename $0) -f <config> [-d <ssldir>]
|
|
|
|
-h | --help : Show this message
|
|
|
|
-f | --config : Openssl configuration file
|
|
|
|
-d | --ssldir : Directory where the certificates will be installed
|
|
|
|
|
|
|
|
ex :
|
|
|
|
$(basename $0) -f openssl.conf -d /srv/ssl
|
|
|
|
EOF
|
|
|
|
}
|
|
|
|
|
|
|
|
# Options parsing
|
|
|
|
while (($#)); do
|
|
|
|
case "$1" in
|
|
|
|
-h | --help) usage; exit 0;;
|
|
|
|
-f | --config) CONFIG=${2}; shift 2;;
|
|
|
|
-d | --ssldir) SSLDIR="${2}"; shift 2;;
|
|
|
|
*)
|
|
|
|
usage
|
|
|
|
echo "ERROR : Unknown option"
|
|
|
|
exit 3
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
done
|
|
|
|
|
|
|
|
if [ -z ${CONFIG} ]; then
|
|
|
|
echo "ERROR: the openssl configuration file is missing. option -f"
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
if [ -z ${SSLDIR} ]; then
|
|
|
|
SSLDIR="/etc/ssl/etcd"
|
|
|
|
fi
|
|
|
|
|
|
|
|
tmpdir=$(mktemp -d /tmp/etcd_cacert.XXXXXX)
|
|
|
|
trap 'rm -rf "${tmpdir}"' EXIT
|
|
|
|
cd "${tmpdir}"
|
|
|
|
|
|
|
|
mkdir -p "${SSLDIR}"
|
|
|
|
|
|
|
|
# Root CA
|
2016-12-13 09:03:35 +00:00
|
|
|
if [ -e "$SSLDIR/ca-key.pem" ]; then
|
|
|
|
# Reuse existing CA
|
|
|
|
cp $SSLDIR/{ca.pem,ca-key.pem} .
|
|
|
|
else
|
|
|
|
openssl genrsa -out ca-key.pem 2048 > /dev/null 2>&1
|
|
|
|
openssl req -x509 -new -nodes -key ca-key.pem -days 10000 -out ca.pem -subj "/CN=etcd-ca" > /dev/null 2>&1
|
|
|
|
fi
|
2016-11-09 10:44:41 +00:00
|
|
|
|
|
|
|
# ETCD member
|
2016-12-13 09:03:35 +00:00
|
|
|
if [ -n "$MASTERS" ]; then
|
|
|
|
for host in $MASTERS; do
|
2017-01-13 16:02:23 +00:00
|
|
|
cn="${host%%.*}"
|
2016-12-27 15:26:22 +00:00
|
|
|
# Member key
|
2016-12-13 09:03:35 +00:00
|
|
|
openssl genrsa -out member-${host}-key.pem 2048 > /dev/null 2>&1
|
2017-01-13 16:02:23 +00:00
|
|
|
openssl req -new -key member-${host}-key.pem -out member-${host}.csr -subj "/CN=etcd-member-${cn}" -config ${CONFIG} > /dev/null 2>&1
|
2016-12-13 09:03:35 +00:00
|
|
|
openssl x509 -req -in member-${host}.csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out member-${host}.pem -days 365 -extensions ssl_client -extfile ${CONFIG} > /dev/null 2>&1
|
2016-12-27 15:26:22 +00:00
|
|
|
|
|
|
|
# Admin key
|
|
|
|
openssl genrsa -out admin-${host}-key.pem 2048 > /dev/null 2>&1
|
2017-01-13 16:02:23 +00:00
|
|
|
openssl req -new -key admin-${host}-key.pem -out admin-${host}.csr -subj "/CN=etcd-admin-${cn}" > /dev/null 2>&1
|
2016-12-27 15:26:22 +00:00
|
|
|
openssl x509 -req -in admin-${host}.csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out admin-${host}.pem -days 365 -extensions ssl_client -extfile ${CONFIG} > /dev/null 2>&1
|
2016-12-13 09:03:35 +00:00
|
|
|
done
|
|
|
|
fi
|
2016-11-09 10:44:41 +00:00
|
|
|
|
2016-12-27 15:26:22 +00:00
|
|
|
# Node keys
|
2016-12-13 09:03:35 +00:00
|
|
|
if [ -n "$HOSTS" ]; then
|
|
|
|
for host in $HOSTS; do
|
2017-01-13 16:02:23 +00:00
|
|
|
cn="${host%%.*}"
|
2016-12-27 15:26:22 +00:00
|
|
|
openssl genrsa -out node-${host}-key.pem 2048 > /dev/null 2>&1
|
2017-01-13 16:02:23 +00:00
|
|
|
openssl req -new -key node-${host}-key.pem -out node-${host}.csr -subj "/CN=etcd-node-${cn}" > /dev/null 2>&1
|
2016-12-27 15:26:22 +00:00
|
|
|
openssl x509 -req -in node-${host}.csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out node-${host}.pem -days 365 -extensions ssl_client -extfile ${CONFIG} > /dev/null 2>&1
|
2016-12-13 09:03:35 +00:00
|
|
|
done
|
|
|
|
fi
|
2016-11-09 10:44:41 +00:00
|
|
|
|
2016-12-28 13:58:37 +00:00
|
|
|
# Grant the group read access
|
|
|
|
chmod g+r *.pem
|
|
|
|
|
2016-11-09 10:44:41 +00:00
|
|
|
# Install certs
|
|
|
|
mv *.pem ${SSLDIR}/
|