adamant-kite-43734
01/26/2024, 5:55 PMcreamy-pencil-82913
01/26/2024, 6:49 PMtls-san:
- $HAPROXY_ADDRESS
on the servers?creamy-pencil-82913
01/26/2024, 6:50 PMcreamy-pencil-82913
01/26/2024, 6:50 PMwonderful-beach-90900
01/26/2024, 8:01 PMwonderful-beach-90900
01/26/2024, 8:09 PMwonderful-beach-90900
01/26/2024, 8:13 PMUnable to connect to the server: x509: certificate signed by unknown authority
i do have a valid cert we use for rancher & one of our downstream clusters, so perhaps i just have to specify that in the same spot. i'll dig into it, thanks.wonderful-beach-90900
01/26/2024, 8:19 PMspec:
valuesContent: |-
controller:
extraArgs:
default-ssl-certificate: "default/tls-wildcard-cert"
That's for the nginx ingress of course, and not the api.creamy-pencil-82913
01/26/2024, 8:24 PMwonderful-beach-90900
01/26/2024, 8:25 PMwonderful-beach-90900
01/26/2024, 8:25 PMcreamy-pencil-82913
01/26/2024, 8:26 PMwonderful-beach-90900
01/26/2024, 8:27 PMcreamy-pencil-82913
01/26/2024, 8:27 PMcreamy-pencil-82913
01/26/2024, 8:27 PMcreamy-pencil-82913
01/26/2024, 8:27 PMwonderful-beach-90900
01/26/2024, 8:29 PMwonderful-beach-90900
01/26/2024, 8:29 PMcreamy-pencil-82913
01/26/2024, 8:31 PMwonderful-beach-90900
01/26/2024, 8:34 PMcreamy-pencil-82913
01/26/2024, 8:36 PMwonderful-beach-90900
01/26/2024, 8:36 PMwonderful-beach-90900
01/26/2024, 8:36 PMwonderful-beach-90900
01/26/2024, 8:37 PMcreamy-pencil-82913
01/26/2024, 8:38 PMwonderful-beach-90900
01/26/2024, 8:39 PMcreamy-pencil-82913
01/26/2024, 8:39 PMcreamy-pencil-82913
01/26/2024, 8:40 PMwonderful-beach-90900
01/26/2024, 8:41 PMwonderful-beach-90900
01/26/2024, 8:47 PM$ openssl s_client -showcerts -connect <fqdn>:6443 | grep -i -A3 "(chain|subject)"
depth=1 CN = rke2-server-ca@1704385527
verify error:num=19:self signed certificate in certificate chain
verify return:1
depth=1 CN = rke2-server-ca@1704385527
verify return:1
depth=0 CN = kube-apiserver
verify return:1
^C
$ openssl s_client -showcerts -connect <control-plane-node>:6443 | grep -i -A3 "(chain|subject)"
Can't use SSL_get_servername
depth=1 CN = rke2-server-ca@1704385527
verify error:num=19:self signed certificate in certificate chain
verify return:1
depth=1 CN = rke2-server-ca@1704385527
verify return:1
depth=0 CN = kube-apiserver
verify return:1
^C
$ openssl s_client -showcerts -connect <fqdn>:443 | grep -i -A3 "(chain|subject)"
depth=1 CN = rke2-server-ca@1704385527
verify error:num=19:self signed certificate in certificate chain
verify return:1
depth=1 CN = rke2-server-ca@1704385527
verify return:1
depth=0 CN = kube-apiserver
verify return:1
wonderful-beach-90900
01/26/2024, 8:48 PMcreamy-pencil-82913
01/26/2024, 8:50 PMwonderful-beach-90900
01/26/2024, 8:51 PMcreamy-pencil-82913
01/26/2024, 8:52 PMcreamy-pencil-82913
01/26/2024, 8:53 PMcreamy-pencil-82913
01/26/2024, 8:53 PMwonderful-beach-90900
01/26/2024, 8:54 PMwonderful-beach-90900
01/26/2024, 8:56 PMcreamy-pencil-82913
01/26/2024, 8:57 PMcreamy-pencil-82913
01/26/2024, 8:57 PMwonderful-beach-90900
01/26/2024, 8:57 PMcreamy-pencil-82913
01/26/2024, 8:57 PMwonderful-beach-90900
01/26/2024, 9:03 PMwonderful-beach-90900
01/26/2024, 9:12 PMwonderful-beach-90900
01/26/2024, 9:12 PMwonderful-beach-90900
01/26/2024, 9:16 PMwonderful-beach-90900
01/26/2024, 9:18 PMcreamy-pencil-82913
01/26/2024, 9:25 PMwonderful-beach-90900
01/26/2024, 9:42 PMwonderful-beach-90900
01/26/2024, 9:43 PM