A certificate-request generator for whole clusters
Generate keys and SAN certificate requests for every host centrally, without SSH access to any of them.
My contribution
Sole author
Tools used
- Bash
- OpenSSL
DetailsSole author
Enabling TLS across a Cloudera cluster and its neighbours (data integration, modelling and Windows servers) means a certificate request for every host, each with the right subject alternative names.
- Reads a simple
fqdn | ip | extra SANsinventory. - Creates or reuses a shared key passphrase, then generates an encrypted RSA key and a CSR per host with DNS and IP SANs and server and client authentication EKUs.
- Verifies the subject, SANs and EKUs of each request, writes per-host output folders and prints a summary.
- Needs no SSH access to the target hosts.
Domains Security & governance · CI/CD & automation
Code Public release pending a final clean-up of example defaults.