This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
решение_freeipa [2026/02/15 07:21] val [Отладка] |
решение_freeipa [2026/02/19 15:14] (current) val [Создание ключа и сертификата для стороннего сервиса] |
||
|---|---|---|---|
| Line 226: | Line 226: | ||
| ipa dnsrecord-add corpX.un keycloak --a-rec="192.168.X.64" | ipa dnsrecord-add corpX.un keycloak --a-rec="192.168.X.64" | ||
| - | sleep 5 | ||
| ipa host-add keycloak.corpX.un | ipa host-add keycloak.corpX.un | ||
| Line 234: | Line 233: | ||
| openssl req -new -key /data/keycloak.key -subj '/CN=keycloak.corpX.un/O=CORPX.UN' -addext 'subjectAltName=DNS:keycloak.corpX.un' -out /data/keycloak.req | openssl req -new -key /data/keycloak.key -subj '/CN=keycloak.corpX.un/O=CORPX.UN' -addext 'subjectAltName=DNS:keycloak.corpX.un' -out /data/keycloak.req | ||
| ipa cert-request /data/keycloak.req --principal=HTTP/keycloak.corpX.un --certificate-out=/data/keycloak.crt | ipa cert-request /data/keycloak.req --principal=HTTP/keycloak.corpX.un --certificate-out=/data/keycloak.crt | ||
| + | |||
| server# scp /opt/freeipa-data/keycloak.* kube1:/tmp/ | server# scp /opt/freeipa-data/keycloak.* kube1:/tmp/ | ||