This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
решение_freeipa [2025/10/02 13:27] val [Управление сертификатами] |
решение_freeipa [2025/10/02 18:18] (current) val [Управление сертификатами] |
||
---|---|---|---|
Line 134: | Line 134: | ||
[root@server ~]# host gate|client1 | [root@server ~]# host gate|client1 | ||
+ | </code> | ||
+ | |||
+ | ===== Управление пользователями ===== | ||
+ | <code> | ||
+ | [root@server ~]# ipa user-add user1 --first="Иван" --last="Иванов" --password | ||
+ | |||
+ | [root@server ~]# #ipa passwd user1 | ||
</code> | </code> | ||
Line 152: | Line 159: | ||
===== Управление сертификатами ===== | ===== Управление сертификатами ===== | ||
<code> | <code> | ||
+ | [root@server ~]# cat /etc/ipa/ca.crt | ||
+ | |||
+ | gate# ipa-getcert request -f /root/gate.crt -k /root/gate.key | ||
+ | </code> | ||
+ | * [[Пакет OpenSSL#Создание пользовательского сертификата, подписанного CA]] | ||
+ | <code> | ||
+ | client1# ipa cert-request --principal=user1 --certificate-out=user1.crt user1.req | ||
+ | </code> | ||
+ | |||
+ | <code> | ||
+ | |||
server.corp13.un:~# cat /opt/freeipa-data/etc/ipa/ca.crt | server.corp13.un:~# cat /opt/freeipa-data/etc/ipa/ca.crt | ||
Line 162: | Line 180: | ||
- | gate.corp13.un:~# ipa-getcert request -f /root/gate.crt -k /root/gate.key -K host/gate.corp13.un | + | |
###server.corp13.un:~# scp kube1:webd-k8s/webd.req /opt/freeipa-data/ | ###server.corp13.un:~# scp kube1:webd-k8s/webd.req /opt/freeipa-data/ |