본문 바로가기
WIKI 기술 지식 베이스

만료된 인증서 교체

원문 보기 위키 갱신

TLS 인증서 중 일부가 만료에 가까워졌는데 cert-manager 같은 외부 인증서 관리 솔루션에 의존하지 않는다면, Manually Rotating Control Plane TLS Credentials 문서를 따라 다운타임 없이 업데이트할 수 있어요. 하지만 인증서 중 하나가 이미 만료됐다면 메시는 이미 무효 상태이며, 다운타임을 피하려는 어떤 조치도 좋은 결과를 보장하지 못해요. 이 경우 만료된 인증서를 유효한 인증서로 교체해야 해요.

출처: Linkerd Replacing expired certificates

본문

발급자 인증서만 교체

발급자(issuer) 인증서가 만료됐을 수 있어요. 이 경우 linkerd check --proxy를 실행하면 다음과 유사한 출력이 나와요:

linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
√ trust roots are within their validity period
√ trust roots are valid for at least 60 days
√ issuer cert is using supported crypto algorithm
× issuer cert is within its validity period
    issuer certificate is not valid anymore. Expired on 2019-12-19T09:21:08Z
    see https://linkerd.io/2/checks/#l5d-identity-issuer-cert-is-time-valid for hints

이 상황에서, 수동으로 제공한 trust root로 Linkerd를 설치했고 그 키를 가지고 있다면, 아이덴티티 발급자 인증서를 회전시키는 설명을 따라 만료된 인증서를 업데이트할 수 있어요.

루트 및 발급자 인증서 교체

루트 인증서가 만료됐거나 루트 키가 없다면, 루트와 발급자 인증서를 동시에 교체해야 해요. 루트가 만료됐다면 linkerd check가 다음과 유사한 오류를 출력해 표시해줘요:

linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
× trust roots are within their validity period
    Invalid roots:
        * 272080721524060688352608293567629376512 identity.linkerd.cluster.local not valid anymore. Expired on 2019-12-19T10:05:31Z
    see https://linkerd.io/2/checks/#l5d-identity-roots-are-time-valid for hints

Generating your own mTLS root certificates 문서를 따라 새 루트와 발급자 인증서를 만들 수 있어요. 그런 다음 linkerd upgrade 명령을 사용해요:

linkerd upgrade \
    --identity-issuer-certificate-file=./issuer-new.crt \
    --identity-issuer-key-file=./issuer-new.key \
    --identity-trust-anchors-file=./ca-new.crt \
    --force \
    | kubectl apply -f -

보통 upgrade는 메시된 파드가 사용하는 루트와 호환되지 않는 발급자 인증서를 사용하는 것을 막아줘요. 하지만 우리는 루트와 발급자 인증서를 동시에 업데이트하고 있으므로 이 검사가 필요 없어요. 따라서 --force 플래그를 사용해 이 오류를 무시해요.

trust bundle이 업데이트된 후 파드가 재시작되는 동안 linkerd check --proxy를 실행하면, 현재 trust bundle이 없는 파드에 대한 경고가 보일 거예요:

linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
√ trust roots are within their validity period
√ trust roots are valid for at least 60 days
√ issuer cert is using supported crypto algorithm
√ issuer cert is within its validity period
√ issuer cert is valid for at least 60 days
√ issuer cert is issued by the trust root

linkerd-identity-data-plane
---------------------------
‼ data plane proxies certificate match CA
    Some pods do not have the current trust bundle and must be restarted:
        * linkerd/linkerd-controller-5b69fd4fcc-7skqb
        * linkerd/linkerd-destination-749df5c74-brchg
        * linkerd/linkerd-prometheus-74cb4f4b69-kqtss
        * linkerd/linkerd-proxy-injector-cbd5545bd-rblq5
        * linkerd/linkerd-sp-validator-6ff949649f-gjgfl
        * linkerd/linkerd-tap-7b5bb954b6-zl9w6
        * linkerd/linkerd-web-84c555f78-v7t44
    see https://linkerd.io/2/checks/#l5d-identity-data-plane-proxies-certs-match-ca for hints

이 경고들은 재시작이 완료되면 사라져요. 재시작이 끝나면 kubectl rollout restart를 사용해 메시된 워크로드를 재시작해 설정을 최신 상태로 유지할 수 있어요. 그 작업이 끝나면 linkerd check가 경고나 오류 없이 실행되어야 해요:

linkerd-identity
----------------
√ certificate config is valid
√ trust roots are using supported crypto algorithm
√ trust roots are within their validity period
√ trust roots are valid for at least 60 days
√ issuer cert is using supported crypto algorithm
√ issuer cert is within its validity period
√ issuer cert is valid for at least 60 days
√ issuer cert is issued by the trust root

linkerd-identity-data-plane
---------------------------
√ data plane proxies certificate match CA

더 알아보기 (Learn more)