-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathauto-tls.sh
134 lines (84 loc) · 3.69 KB
/
auto-tls.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
#!/bin/sh
# -------------------------------------------------------------
# Docker TLS certificate sign script
# -------------------------------------------------------------
# -------------------------------------------------------------
# Configure certificate information
# Author Brian
# configure IP *(Required):
ip=""
# configure password *(Required):
password=""
# configure filename *(Required):
filename=""
# default
days=1000
# -------------------------------------------------------------
# delete all .pem file
rm -rf ./*.pem
# generate CA key
echo -e "\033[34m generate CA key \033[0m"
openssl genrsa -aes256 -passout "pass:$password" -out "ca-key-$filename.pem" 4096
# generate CA certificate
echo -e "\033[34m generate CA certificate \033[0m"
openssl req -new -x509 -days $days -key "ca-key-$filename.pem" -sha256 -passin "pass:$password" -subj "/CN=$ip" -out "ca-$filename.pem"
# generate Server key
echo -e "\033[34m generate server key \033[0m"
openssl genrsa -out "server-key-$filename.pem" 4096
# generate Server certificate
echo -e "\033[34m generate server certificate \033[0m"
openssl req -new -sha256 -key "server-key-$filename.pem" -subj "/CN=$ip" -out server.csr
echo "subjectAltName = IP:$ip,IP:127.0.0.1" >> extfile.cnf
echo "extendedKeyUsage = serverAuth" >> extfile.cnf
openssl x509 -req -days $days -sha256 -in server.csr -passin "pass:$password" -CA "ca-$filename.pem" -CAkey "ca-key-$filename.pem" -CAcreateserial -out "server-cert-$filename.pem" -extfile extfile.cnf
rm -rf extfile.cnf
# generate Client certificate
echo -e "\033[34m generate client certificate \033[0m"
openssl genrsa -out "key-$filename.pem" 4096
openssl req -subj "/CN=client" -new -key "key-$filename.pem" -out client.csr
echo extendedKeyUsage = clientAuth >> extfile.cnf
openssl x509 -req -days $days -sha256 -in client.csr -passin "pass:$password" -CA "ca-$filename.pem" -CAkey "ca-key-$filename.pem" -CAcreateserial -out "cert-$filename.pem" -extfile extfile.cnf
# delete csr file
echo -e "\033[34m delete unnecessary files \033[0m"
rm -rf server.csr client.csr extfile.cnf "ca-$filename.srl"
# write readme file
cat << EOF > README-SERVER.txt
1. Configure the docker daemon.json file
$ cd /etc/docker/
$ vi daemon.json
{
"tlsverify": true,
"tlscacert": "/etc/cert path", // ca-xxx.pem
"tlscert": "/etc/cert path", // server-cert-xxx.pem
"tlskey": "/etc/cert path", // server-key-xxx.pem
"hosts": ["tcp://0.0.0.0:2375", "unix:///var/run/docker.sock"]
}
$ systemctl daemon-reload
$ systemctl restart docker
----------------------------------
2. Modify docker.service
tlscacert: ca-xxx.pem
tlscert: server-cert-xxx.pem
tlskey: server-key-xxx.pem
$ vi /usr/lib/systemd/system/docker.service
Add modification code:
ExecStart=/usr/bin/dockerd --tlsverify --tlscacert=/etc/<cert path> --tlscert=/etc/<cert path> --tlskey=/etc/<cert path> -H tcp://0.0.0.0:2375 -H unix:///var/run/docker.sock
$ systemctl daemon-reload
$ systemctl restart docker
EOF
cat << EOF > README-CLIENT.txt
Connection method
Upload the certificate to the specified server
docker --tlsverify --tlscacert=ca.pem --tlscert=cert.pem --tlskey=key.pem -H tcp://ip:2375 ps
EOF
# package file
echo -e "\033[34m Package upload file: client \033[0m"
tar zcvf tls-client.tar.gz "ca-$filename.pem" "cert-$filename.pem" "key-$filename.pem" "README-CLIENT.txt"
echo -e "\033[34m Package upload file: server \033[0m"
tar zcvf tls-server.tar.gz "ca-$filename.pem" "server-cert-$filename.pem" "server-key-$filename.pem" "README-SERVER.txt"
# sleep 2 second
sleep 2
# delete all suffix pem file
echo -e "\033[34m delete all suffix pem file and txt file \033[0m"
rm -rf ./*.pem ./*.txt
echo -e "\e[1;32m All operation is done! \e[0m"