mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-07-22 11:21:47 +00:00
Merge pull request #44638 from ixdy/porter-cert
Automatic merge from submit-queue (batch tested with PRs 44222, 44614, 44292, 44638) Update dummy certificate used in porter image **What this PR does / why we need it**: the dummy certificate used for the porter image is incompatible with go1.8+ since it is missing NULL parameters for the RSA public key. I haven't pushed the new porter image yet. I verified that this appears to fix the issue. Based on https://github.com/kubernetes/kubernetes/issues/38228#issuecomment-280213590, for the old cert: ```console $ openssl x509 -in localhost.crt -outform der | openssl asn1parse -inform der -i ... 105:d=4 hl=2 l= 9 prim: OBJECT :rsaEncryption 116:d=3 hl=2 l= 75 prim: BIT STRING ... ``` and the new cert: ```console $ openssl x509 -in localhost.crt -outform der | openssl asn1parse -inform der -i ... 127:d=4 hl=2 l= 9 prim: OBJECT :rsaEncryption 138:d=4 hl=2 l= 0 prim: NULL 140:d=3 hl=4 l= 271 prim: BIT STRING ... ``` **Release note**: ```release-note NONE ``` cc @liggitt @lavalamp @luxas
This commit is contained in:
commit
d264cdf312
@ -2,9 +2,9 @@ This directory contains go source, Dockerfile and Makefile for making a test
|
|||||||
container which serves requested data on ports specified in ENV variables.
|
container which serves requested data on ports specified in ENV variables.
|
||||||
|
|
||||||
The included localhost.crt is a PEM-encoded TLS cert with SAN IPs
|
The included localhost.crt is a PEM-encoded TLS cert with SAN IPs
|
||||||
"127.0.0.1" and "[::1]", expiring at the last second of 2049 (the end
|
"127.0.0.1" and "[::1]", expiring in January 2084, generated from
|
||||||
of ASN.1 time), generated from src/crypto/tls:
|
src/crypto/tls:
|
||||||
go run generate_cert.go --rsa-bits 512 --host 127.0.0.1,::1,example.com --ca --start-date "Jan 1 00:00:00 1970" --duration=1000000h
|
go run generate_cert.go --rsa-bits 2048 --host 127.0.0.1,::1,example.com --ca --start-date "Jan 1 00:00:00 1970" --duration=1000000h
|
||||||
|
|
||||||
To use a different cert/key, mount them into the pod and set the
|
To use a different cert/key, mount them into the pod and set the
|
||||||
CERT_FILE and KEY_FILE environment variables to the desired paths.
|
CERT_FILE and KEY_FILE environment variables to the desired paths.
|
||||||
|
@ -1,10 +1,19 @@
|
|||||||
-----BEGIN CERTIFICATE-----
|
-----BEGIN CERTIFICATE-----
|
||||||
MIIBdzCCASOgAwIBAgIBADALBgkqhkiG9w0BAQUwEjEQMA4GA1UEChMHQWNtZSBD
|
MIIDGTCCAgGgAwIBAgIRAOAAu25xDsyahNZBSXsUWhswDQYJKoZIhvcNAQELBQAw
|
||||||
bzAeFw03MDAxMDEwMDAwMDBaFw00OTEyMzEyMzU5NTlaMBIxEDAOBgNVBAoTB0Fj
|
EjEQMA4GA1UEChMHQWNtZSBDbzAgFw03MDAxMDEwMDAwMDBaGA8yMDg0MDEyOTE2
|
||||||
bWUgQ28wWjALBgkqhkiG9w0BAQEDSwAwSAJBAN55NcYKZeInyTuhcCwFMhDHCmwa
|
MDAwMFowEjEQMA4GA1UEChMHQWNtZSBDbzCCASIwDQYJKoZIhvcNAQEBBQADggEP
|
||||||
IUSdtXdcbItRB/yfXGBhiex00IaLXQnSU+QZPRZWYqeTEbFSgihqi1PUDy8CAwEA
|
ADCCAQoCggEBAJ3bom8WHGFTGbEse2k6bhAQxjnxJvl03+DngrnrbTUXu6zw1k/b
|
||||||
AaNoMGYwDgYDVR0PAQH/BAQDAgCkMBMGA1UdJQQMMAoGCCsGAQUFBwMBMA8GA1Ud
|
nk11ZHfIZPpnGoySEWYLqHBiRiMvGwRgGAu3Grtf3mfeInjs1aeXFepaXc7KRm4b
|
||||||
EwEB/wQFMAMBAf8wLgYDVR0RBCcwJYILZXhhbXBsZS5jb22HBH8AAAGHEAAAAAAA
|
z/fw3ABwvJQ9rJw9+Xb8zZqBUpoLZzjjUDTk22pNAS9XMjRSOUtLzPEYH5fL61Ev
|
||||||
AAAAAAAAAAAAAAEwCwYJKoZIhvcNAQEFA0EAAoQn/ytgqpiLcZu9XKbCJsJcvkgk
|
J7FD7twinaUbZAUQvg1nsLELt87t+bo964p6p+z77g6TBa6PPezVndzmR3F0VPHV
|
||||||
Se6AbGXgSlq+ZCEVo0qIwSgeBqmsJxUu7NCSOwVJLYNEBO2DtIxoYVk+MA==
|
RLPOd9gqwboFchho3z68ZNb4rnKg1fybuaOPXmwBKDRkaQMAzlnDVe246rx6O6wg
|
||||||
-----END CERTIFICATE-----
|
bJKvxaXviejcKMPuZ0EDjxzoWHjnh6ooiOUCAwEAAaNoMGYwDgYDVR0PAQH/BAQD
|
||||||
|
AgKkMBMGA1UdJQQMMAoGCCsGAQUFBwMBMA8GA1UdEwEB/wQFMAMBAf8wLgYDVR0R
|
||||||
|
BCcwJYILZXhhbXBsZS5jb22HBH8AAAGHEAAAAAAAAAAAAAAAAAAAAAEwDQYJKoZI
|
||||||
|
hvcNAQELBQADggEBAGXwn/vvQA0HDbW8WnTAWpvzAfaO6j6wAsDw6sMtcQDovyuk
|
||||||
|
Q3FCkZJBQ8a1mClBGXveWaDr3bU833IVQIBTvsLmLmQ9t2YrrtbEWyfgszqGK4C7
|
||||||
|
kIbyUXe7EFiJWP7A0WqwiHtOMbk8j848/CmiKI4D5p+YgXVgurP1IQ5t79Q/ZDyD
|
||||||
|
EJt+HtJvrCo9ZHacmC865eoJZG6sG2Ul64IItRYDZbr55UKViJ8r81Q67nNCv/8D
|
||||||
|
f4/K2f+miPVaTMLAll6zCT78I+3iSPPO3yCmL/2Udp4a10Jqrfv+hbf8t4DUcqlz
|
||||||
|
4XFrUHspRDZcGXFILnAsNOpfK7UmUU0wkbFghkI=
|
||||||
|
-----END CERTIFICATE-----
|
||||||
|
@ -1,9 +1,27 @@
|
|||||||
-----BEGIN RSA PRIVATE KEY-----
|
-----BEGIN RSA PRIVATE KEY-----
|
||||||
MIIBPAIBAAJBAN55NcYKZeInyTuhcCwFMhDHCmwaIUSdtXdcbItRB/yfXGBhiex0
|
MIIEogIBAAKCAQEAnduibxYcYVMZsSx7aTpuEBDGOfEm+XTf4OeCuettNRe7rPDW
|
||||||
0IaLXQnSU+QZPRZWYqeTEbFSgihqi1PUDy8CAwEAAQJBAQdUx66rfh8sYsgfdcvV
|
T9ueTXVkd8hk+mcajJIRZguocGJGIy8bBGAYC7cau1/eZ94ieOzVp5cV6lpdzspG
|
||||||
NoafYpnEcB5s4m/vSVe6SU7dCK6eYec9f9wpT353ljhDUHq3EbmE4foNzJngh35d
|
bhvP9/DcAHC8lD2snD35dvzNmoFSmgtnOONQNOTbak0BL1cyNFI5S0vM8Rgfl8vr
|
||||||
AekCIQDhRQG5Li0Wj8TM4obOnnXUXf1jRv0UkzE9AHWLG5q3AwIhAPzSjpYUDjVW
|
US8nsUPu3CKdpRtkBRC+DWewsQu3zu35uj3rinqn7PvuDpMFro897NWd3OZHcXRU
|
||||||
MCUXgckTpKCuGwbJk7424Nb8bLzf3kllAiA5mUBgjfr/WtFSJdWcPQ4Zt9KTMNKD
|
8dVEs8532CrBugVyGGjfPrxk1viucqDV/Ju5o49ebAEoNGRpAwDOWcNV7bjqvHo7
|
||||||
EUO0ukpTwEIl6wIhAMbGqZK3zAAFdq8DD2jPx+UJXnh0rnOkZBzDtJ6/iN69AiEA
|
rCBskq/Fpe+J6Nwow+5nQQOPHOhYeOeHqiiI5QIDAQABAoIBAG1wRmWTQ6upjAdL
|
||||||
1Aq8MJgTaYsDQWyU/hDq5YkDJc9e9DSCvUIzqxQWMQE=
|
2mcyjflvV6315NpOz6NBfVzdvcFwKbmU4k9M56u1tihg8riy4DISViOT83uudgeQ
|
||||||
-----END RSA PRIVATE KEY-----
|
cb+Pyzvb/plmtm72DpodP2ZHlXb6nUxu6XMOrxiqkCtx/Rscwt0zDg8S5ou2GokX
|
||||||
|
XMGQvhtdikxhBHBImFKzqmrsKzH9O3oalpXCHTIHd2aDMkmrMbdjS+SSPBl6yjoz
|
||||||
|
9abnaztO4b0k76Un/648z17Z9R+OvqUvWLCxCL8XBfGd5kEIS3XLB2NlItKpsMPw
|
||||||
|
BTbYp45NaPiQOlgcNeeLZxPatSZ8WUB/28dvWzdGc2n/ybZFZlKxG0IvmjBwI97a
|
||||||
|
vkMSl8UCgYEA0WNFh9jpz3nKngbrOHx3vy6HkI7jots3kW8Lcml1uRInOOG6nerl
|
||||||
|
m0SSP/tBm4vMK0lzwlDfaTPP6UqvHnB4KI9dg3PvuDTskxC1MrmE/ZXspUHNFlCa
|
||||||
|
T5UZgXwd6KUv0bc+93KIAY/QiriYmE0DeK6vU+YDBgA4pqcywyotK4sCgYEAwP+/
|
||||||
|
OBajqNJqspiKo6UveKCHo0+L6+rrQiE3wAKH37I901NFQLBzKBtXGB+DhdrqQuYh
|
||||||
|
V+DfiXktkf3fqSz4lK5eomIrw+jxPVfgIDHjPUSJoya8sxPUv5E5Vu7dv6EcinE1
|
||||||
|
fssMGDzs4lcV2GT3bng5T9bgK1rjc191iCOva08CgYBy9Flb946FxYujrpC89jiX
|
||||||
|
0WfDyW7YHhon0hsquRNUg87cv7DAuhFMaR0R21NtnhZ9PVo8OEIvc66VmdcCkySk
|
||||||
|
v/DLFn9pVkT7iJSyQH/u6Lx/Dd0WfzH4txbFq+qPqwDR1hTPrSVWFiqbvjSoiL97
|
||||||
|
JgxDt2e5h62ScQDBfQpHeQKBgHZocdjniuE4t117WROtdMJ9OrpnQ2Eqb8vStXGI
|
||||||
|
G/SSVnwgyow1tXEV1QlnzDmDZdZFeo9/16VwQxUevOn+PUR69nSJ5m/7qoYIM+mM
|
||||||
|
se4U7py6V2tG72/YmWVMh5/aKLiHXFq+GF2Gg48Z/r0UtPmBqSfinQX8bS+LkYBE
|
||||||
|
5IrhAoGAOfnnAOAjSqKTZF5L7CJJHBYYowtcdgKdBfELWP+eWRgXPWS7sWuAE670
|
||||||
|
STDfr0KxnkrMOGv0SPpN7qVh9zPrFtfXzLkj67g7ydxUIN55cgDoPFLpCVRX87HU
|
||||||
|
nbVwcbxVjeBqQ1CyN329adNI1LsnPqy59LzBxDM/JWa47A6Y7Vc=
|
||||||
|
-----END RSA PRIVATE KEY-----
|
||||||
|
Loading…
Reference in New Issue
Block a user