Reorganize instructions on how to use CFSSL
CFSSL is CloudFlare's PKI / TLS Switzerland × ×. It is not only a command line tool, but also a HTTP API server for signing, verifying and bundling TLS certificates.
1. Download and install CFSSL (HTTP API tool for signing, verifying, and bundling TLS certificates) (master node)
Wget https://pkg.cfssl.org/R1.2/cfssl-certinfo_linux-amd64
Wget https://pkg.cfssl.org/R1.2/cfssl_linux-amd64
Wget https://pkg.cfssl.org/R1.2/cfssljson_linux-amd64
Mv cfssl-certinfo_linux-amd64 / usr/local/bin/cfssl-certinfo
Mv cfssl_linux-amd64 / usr/local/bin/cfssl
Mv https://pkg.cfssl.org/R1.2/cfssljson_linux-amd64 / usr/local/bin/cfssljson
Chmod + x / usr/local/bin/cfssl / usr/local/bin/cfssl-certinfo / usr/local/bin/cfssljson
2 create CA (Certificate Authority) (master node) mkdir / root/ssl cd / root/ssl cfssl print-defaults config > config.json # default configuration template cfssl print-defaults csr > csr.json # default csr request template # create the following ca-config.json file based on the format of the config.json file # the expiration time is set to 87600h cat > ca-config.json