| 방식 | 설명 | 적용 조건 |
|---|---|---|
| Use Case 2 | CM 이 Intermediate CA 가 되고, 그 CSR 을 사설 Root CA 가 서명 | 신규 설치(호스트 추가 전) |
| Use Case 3 | 호스트별 인증서를 Root CA 로 직접 서명해 업로드 | 신규 · 기존 클러스터 모두 |
기존 클러스터에 Auto-TLS 를 켜려면 Use Case 3 이다. CM 의 Administration → Security → Enable Auto-TLS 에서 호스트별 인증서 · 키 · CA 체인을 올린다.
# /root/config.ini
[General]
ca_key_args=2048
host_key_args=2048
ca_dn="CN=cm-server.example.com,DC=MyCompany,DC=Internal"
export JAVA_HOME=/usr/lib/jvm/java-1.8.0-openjdk
systemctl stop cloudera-scm-server
/opt/cloudera/cm-agent/bin/certmanager --location /var/lib/cloudera-scm-server/certmanager \
setup --config ./config.ini --configure-services --stop-at-csr
openssl req -in /var/lib/cloudera-scm-server/certmanager/CMCA/private/ca_csr.pem -noout -text
Root CA 쪽에서 CSR 을 CA 인증서로 서명한다. 서명 결과에 CA:TRUE, pathlen:0 과 Certificate Sign, CRL Sign 키 사용이 들어 있어야 한다.
openssl x509 -req -in ca_csr.pem -CA rootca.pem -CAkey rootca.key -CAcreateserial \
-out intermediate.pem -days 3650 -sha256 -extensions v3_ca -extfile openssl.cnf
cat intermediate.pem rootca.pem > cm_cert_chain.pem
/opt/cloudera/cm-agent/bin/certmanager --location /var/lib/cloudera-scm-server/certmanager \
setup --configure-services --trusted-ca-certs rootca.pem --signed-ca-cert cm_cert_chain.pem
systemctl start cloudera-scm-server
ECS 설치 마법사의 "Upload the CA certificate used to verify the Docker repository" 에는 Harbor 서버 인증서가 아니라 그 인증서를 서명한 CA 인증서(ca.crt)를 올린다. harbor.yml 의 certificate 경로 옆이나 /etc/docker/certs.d/<harbor-host>/ca.crt 에 있다. openssl x509 -in ca.crt -noout -text | grep -A1 "Basic Constraints" 가 CA:TRUE 여야 한다. Harbor 인증서 경로를 바꿨으면 ./prepare → docker-compose down(-v 없이) → docker-compose up -d 순으로 반영한다.
Auto-TLS 를 켜고 CM 만 재기동한 뒤 Agent 로그에 M2Crypto.SSL.Checker.WrongHost: Peer certificate subjectAltName does not match host, expected 182.x.x.x 가 나면 Agent 가 CM 을 IP 로 부르고 있는 것이다. 인증서의 SAN 은 호스트명뿐이다.
sed -i 's/^server_host=.*/server_host=cm-host.example.com/' /etc/cloudera-scm-agent/config.ini
systemctl restart cloudera-scm-agent
tail -f /var/log/cloudera-scm-agent/cloudera-scm-agent.log | grep -E "ERROR|Heartbeat"
모든 Agent 호스트에 같은 수정을 한다.