ProductionOwn tooling · used on client engagements2026

A certificate-request generator for whole clusters

Generate keys and SAN certificate requests for every host centrally, without SSH access to any of them.

My contribution

Sole author

Tools used

  • Bash
  • OpenSSL
DetailsSole author

Enabling TLS across a Cloudera cluster and its neighbours (data integration, modelling and Windows servers) means a certificate request for every host, each with the right subject alternative names.

  • Reads a simple fqdn | ip | extra SANs inventory.
  • Creates or reuses a shared key passphrase, then generates an encrypted RSA key and a CSR per host with DNS and IP SANs and server and client authentication EKUs.
  • Verifies the subject, SANs and EKUs of each request, writes per-host output folders and prints a summary.
  • Needs no SSH access to the target hosts.

Domains Security & governance · CI/CD & automation

Trace it in the constellation

Code Public release pending a final clean-up of example defaults.

Search the portfolio

Try:

↑ ↓ to move · Enter to open · Esc to close