2.6.2. Configuring Capsule Server with a Custom SSL Certificate
If you configure Satellite Server to use a custom SSL certificate, you must also configure each of your external Capsule Servers with a distinct custom SSL certificate.
To configure your Capsule Server with a custom certificate, complete the following procedures on each Capsule Server:
2.6.2.1. Creating a Custom SSL Certificate for Capsule Server リンクのコピーリンクがクリップボードにコピーされました!
On Satellite Server, create a custom certificate for your Capsule Server. If you already have a custom SSL certificate for Capsule Server, skip this procedure.
When you configure Capsule Server with custom certificates, note the following considerations:
- You must use the Privacy-Enhanced Mail (PEM) encoding for the SSL certificates.
- You cannot use the same certificate for both Satellite Server and Capsule Server.
- The same Certificate Authority must sign certificates for Satellite Server and Capsule Server.
Procedure
To create a custom SSL certificate, complete the following steps:
To store all the source certificate files, create a directory that is accessible only to the
rootuser.mkdir /root/capsule_cert
# mkdir /root/capsule_certCopy to Clipboard Copied! Toggle word wrap Toggle overflow Create a private key with which to sign the Certificate Signing Request (CSR).
Note that the private key must be unencrypted. If you use a password-protected private key, remove the private key password.
If you already have a private key for this Capsule Server, skip this step.
openssl genrsa -out /root/capsule_cert/capsule_cert_key.pem 4096
# openssl genrsa -out /root/capsule_cert/capsule_cert_key.pem 4096Copy to Clipboard Copied! Toggle word wrap Toggle overflow Create the
/root/capsule_cert/openssl.cnfconfiguration file for the Certificate Signing Request (CSR) and include the following content:Copy to Clipboard Copied! Toggle word wrap Toggle overflow - 1
- In the
[ req_distinguished_name ]section, enter information about your organization. - 2
- Set the certificate’s Common Name
CNto match the fully qualified domain name (FQDN) of your Capsule Server or a wildcard value*. To confirm a FQDN, on that Capsule Server, enter thehostname -fcommand. This is required to ensure that thekatello-certs-checkcommand validates the certificate correctly. If you set a wildcard value, you must add the-t capsuleoption when you use thekatello-certs-checkcommand. - 3
- Set the Subject Alternative Name (SAN)
DNS.1to match the fully qualified domain name (FQDN) of your server.
Generate the Certificate Signing Request (CSR):
openssl req -new \ -key /root/capsule_cert/capsule_cert_key.pem \ -config /root/capsule_cert/openssl.cnf \ -out /root/capsule_cert/capsule_cert_csr.pem
# openssl req -new \ -key /root/capsule_cert/capsule_cert_key.pem \1 -config /root/capsule_cert/openssl.cnf \2 -out /root/capsule_cert/capsule_cert_csr.pem3 Copy to Clipboard Copied! Toggle word wrap Toggle overflow Send the certificate signing request to the Certificate Authority. The same Certificate Authority must sign certificates for Satellite Server and Capsule Server.
When you submit the request, specify the lifespan of the certificate. The method for sending the certificate request varies, so consult the Certificate Authority for the preferred method. In response to the request, you can expect to receive a Certificate Authority bundle and a signed certificate, in separate files.