Changes between Initial Version and Version 1 of GENIRacksHome/OpenGENIRacks/RenewKeystoneKeys


Ignore:
Timestamp:
02/27/15 09:54:54 (9 years ago)
Author:
sdabideen@bbn.com
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • GENIRacksHome/OpenGENIRacks/RenewKeystoneKeys

    v1 v1  
     1Keystone certs expire every year
     2
     3From /etc/keystone/ssl/certs
     4
     5# This makes the Certificate Signing Request (CSR)
     6openssl req -newkey rsa:2048 -keyout signing_key.pem -keyform PEM -out signing_\
     7cert_req.pem -outform PEM -config openssl.conf -nodes
     8Unset
     9Unset
     10Unset
     11Unset
     12Unset
     13US
     14clemson-clemson-control-1
     15
     16
     17openssl ca -config openssl.conf -keyfile cakey.pem -cert ca.pem -in signing_cer\
     18t_req.pem -out signing_cert_new.pem
     19y
     20y
     21
     22
     23Change the permissions of the new cert:
     24chown keystone.keystone signing_cert_new.pem
     25
     26
     27sudo keystone-manage pki_setup  --keystone-user keystone --keystone-group keystone
     28
     29
     30The other openstack services maintain their own copy of the cert, so you must replace them:
     31cp /etc/keystone/ssl/certs/ca.pem /var/lib/nova/keystone-signing/cacert.pem
     32cp /etc/keystone/ssl/certs/signing_cert.pem /var/lib/nova/keystone-signing/signing_cert.pem
     33restart nova-api
     34cp /etc/keystone/ssl/certs/ca.pem /var/lib/cinder/cacert.pem
     35cp /etc/keystone/ssl/certs/signing_cert.pem /var/lib/cinder/signing_cert.pem
     36restart cinder-api
     37cp /etc/keystone/ssl/certs/ca.pem /var/lib/quantum/keystone-signing/cacert.pem
     38cp /etc/keystone/ssl/certs/signing_cert.pem /var/lib/quantum/keystone-signing/signing_cert.pem
     39restart quantum-server
     40cp /etc/keystone/ssl/certs/ca.pem /var/lib/glance/keystone-signing/cacert.pem
     41cp /etc/keystone/ssl/certs/signing_cert.pem /var/lib/glance/keystone-signing/signing_cert.pem
     42restart glance-api
     43restart glance-registry
     44
     45
     46