Doc: fix default server certificate role
This commit is contained in:
parent
c5d63bd6f8
commit
5e31af2ee2
@ -36,10 +36,12 @@
|
|||||||
vault write pki_int/roles/servers_default \
|
vault write pki_int/roles/servers_default \
|
||||||
issuer_ref="$(vault read -field=default pki_int/config/issuers)" \
|
issuer_ref="$(vault read -field=default pki_int/config/issuers)" \
|
||||||
allow_ip_sans=true \
|
allow_ip_sans=true \
|
||||||
allowed_domains="unkin.net,prod*" \
|
allowed_domains="unkin.net, *.unkin.net, localhost" \
|
||||||
allow_subdomains=true \
|
allow_subdomains=true \
|
||||||
allow_bare_domains=true \
|
|
||||||
allow_glob_domains=true \
|
allow_glob_domains=true \
|
||||||
|
allow_bare_domains=true \
|
||||||
|
enforce_hostnames=true \
|
||||||
|
allow_any_name=true \
|
||||||
max_ttl="2160h" \
|
max_ttl="2160h" \
|
||||||
key_bits=4096 \
|
key_bits=4096 \
|
||||||
country="Australia"
|
country="Australia"
|
||||||
@ -49,7 +51,6 @@
|
|||||||
vault write pki_int/issue/servers_default common_name="test.main.unkin.net" ttl="24h"
|
vault write pki_int/issue/servers_default common_name="test.main.unkin.net" ttl="24h"
|
||||||
vault write pki_int/issue/servers_default common_name="*.test.main.unkin.net" ttl="24h"
|
vault write pki_int/issue/servers_default common_name="*.test.main.unkin.net" ttl="24h"
|
||||||
|
|
||||||
|
|
||||||
# remove expired certificates
|
# remove expired certificates
|
||||||
vault write pki_int/tidy tidy_cert_store=true tidy_revoked_certs=true
|
vault write pki_int/tidy tidy_cert_store=true tidy_revoked_certs=true
|
||||||
|
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user