allowed wildcard domain

This commit is contained in:
Konstantin Lebedev
2021-03-10 14:02:13 +05:00
parent 4bf93d6e63
commit 831953c55c
4 changed files with 35 additions and 31 deletions

View File

@@ -48,11 +48,11 @@ clean:
certstrap:
go get github.com/square/certstrap
certstrap --depot-path compose/tls init --passphrase "" --common-name "SeaweedFS CA" || true
certstrap --depot-path compose/tls request-cert --passphrase "" --common-name volume01 || true
certstrap --depot-path compose/tls request-cert --passphrase "" --common-name master01 || true
certstrap --depot-path compose/tls request-cert --passphrase "" --common-name filer01 || true
certstrap --depot-path compose/tls request-cert --passphrase "" --common-name client01 || true
certstrap --depot-path compose/tls sign --CA "SeaweedFS CA" volume01 || true
certstrap --depot-path compose/tls sign --CA "SeaweedFS CA" master01 || true
certstrap --depot-path compose/tls sign --CA "SeaweedFS CA" filer01 || true
certstrap --depot-path compose/tls sign --CA "SeaweedFS CA" client01 || true
certstrap --depot-path compose/tls request-cert --passphrase "" --common-name volume01.dev || true
certstrap --depot-path compose/tls request-cert --passphrase "" --common-name master01.dev || true
certstrap --depot-path compose/tls request-cert --passphrase "" --common-name filer01.dev || true
certstrap --depot-path compose/tls request-cert --passphrase "" --common-name client01.dev || true
certstrap --depot-path compose/tls sign --CA "SeaweedFS CA" volume01.dev || true
certstrap --depot-path compose/tls sign --CA "SeaweedFS CA" master01.dev || true
certstrap --depot-path compose/tls sign --CA "SeaweedFS CA" filer01.dev || true
certstrap --depot-path compose/tls sign --CA "SeaweedFS CA" client01.dev || true

View File

@@ -1,13 +1,10 @@
WEED_GRPC_CA=/etc/seaweedfs/tls/SeaweedFS_CA.crt
WEED_GRPC_MASTER_CERT=/etc/seaweedfs/tls/master01.crt
WEED_GRPC_MASTER_KEY=/etc/seaweedfs/tls/master01.key
WEED_GRPC_VOLUME_CERT=/etc/seaweedfs/tls/volume01.crt
WEED_GRPC_VOLUME_KEY=/etc/seaweedfs/tls/volume01.key
WEED_GRPC_FILER_CERT=/etc/seaweedfs/tls/filer01.crt
WEED_GRPC_FILER_KEY=/etc/seaweedfs/tls/filer01.key
WEED_GRPC_CLIENT_CERT=/etc/seaweedfs/tls/client01.crt
WEED_GRPC_CLIENT_KEY=/etc/seaweedfs/tls/client01.key
WEED_GRPC_MASTER_ALLOWED_COMMONNAMES="volume01,master01,filer01,client01"
WEED_GRPC_VOLUME_ALLOWED_COMMONNAMES="volume01,master01,filer01,client01"
WEED_GRPC_FILER_ALLOWED_COMMONNAMES="volume01,master01,filer01,client01"
WEED_GRPC_CLIENT_ALLOWED_COMMONNAMES="volume01,master01,filer01,client01"
WEED_GRPC_ALLOWED_WILDCARD_DOMAIN=".dev"
WEED_GRPC_MASTER_CERT=/etc/seaweedfs/tls/master01.dev.crt
WEED_GRPC_MASTER_KEY=/etc/seaweedfs/tls/master01.dev.key
WEED_GRPC_VOLUME_CERT=/etc/seaweedfs/tls/volume01.dev.crt
WEED_GRPC_VOLUME_KEY=/etc/seaweedfs/tls/volume01.dev.key
WEED_GRPC_FILER_CERT=/etc/seaweedfs/tls/filer01.dev.crt
WEED_GRPC_FILER_KEY=/etc/seaweedfs/tls/filer01.dev.key
WEED_GRPC_CLIENT_CERT=/etc/seaweedfs/tls/client01.dev.crt
WEED_GRPC_CLIENT_KEY=/etc/seaweedfs/tls/client01.dev.key