Configure certificates
Products: FastReport Corporate Server
You need to create a certificate for the report server to work.
To create a self-signed certificate, use the following commands:
#!/bin/sh
openssl req -x509 -nodes -new -sha256 -days 1024 -newkey rsa:2048 -keyout RootCA.key -out RootCA.pem -subj "/C=US/CN=debian-master.fast-report.com"
openssl x509 -outform pem -in RootCA.pem -out RootCA.crt
openssl pkcs12 -export -out ./certificate.pfx -inkey RootCA.key -in RootCA.crt
To create a secret, run the following commands:
NAMESPACE=fr-corporate-server
SECRET_VOLUME_NAME=corporate-volume-secret
kubectl create namespace $NAMESPACE
kubectl create secret generic $SECRET_VOLUME_NAME -n $NAMESPACE --from-file=certificate.pfx
Alternative method of certificate generation suggested by the product user
- Create and edit the
san.cnffile:
[ req ]
default_bits = 2048
default_md = sha256
distinguished_name = req_distinguished_name
req_extensions = v3_req
[ req_distinguished_name ]
countryName = CN # C=
stateOrProvinceName = Shanghai # ST=
localityName = MyCity # L=
#postalCode = 200000 # L/postalcode=
#streetAddress = "My Address" # L/street=
organizationName = My Corporation # O=
organizationalUnitName = My Department # OU=
commonName = myname.mysoftware.mycorporation.com # CN=
emailAddress = myname@example.com # CN/emailAddress=
[ v3_req ]
subjectAltName = @alt_names
[ alt_names ]
DNS.1 = myname.mysoftware.mycorporation.com
#DNS.2 = other2.com
#DNS.3 = other3.coM
- Generate a certificate:
openssl req -x509 -nodes -days 365 -subj "/C=CN/ST=Shanghai/L=Shanghai/O=My Corporation/OU=My Department/CN=myname.mysoftware.mycorporation.com/emailAddress=myname@example.com" -keyout privateKey.pem -out public.crt -config san.cnf -extensions v3_req
openssl pkcs12 -export -out ./certificate.pfx -inkey privateKey.key -in public.crt
- Create a secret in the cloud server:
NAMESPACE=fr-corporate-server
SECRET_VOLUME_NAME=corporate-volume-secret
kubectl create namespace $NAMESPACE
kubectl create secret generic $SECRET_VOLUME_NAME -n $NAMESPACE --from-file=certificate.pfx