/srv/irclogs.ubuntu.com/2017/02/18/#juju.txt

mbruzekbdx: there is an extra SANS section to the cert that you can specify. you will have to look at the code, but you may be able to insert the fqdn in the extra sans (if it is not already).00:01
mbruzekbdx: to view the cert you can run a command to introspect the certificate or key.00:05
mbruzekopenssl x509 -text -in /usr/local/share/ca-certificates/easyrsa.crt00:05
mbruzekbdx: The section you want to look for is X509v3 Subject Alternative Name00:09
mbruzek openssl x509 -text -in /var/lib/juju/agents/unit-easyrsa-0/charm/EasyRSA-3.0.1/pki/issued/kubernetes-master_0.crt00:10
bdxmbruzek: so, I was able to get my fqdn into the certs by specifying it here https://jujucharms.com/u/containers/kubernetes-master/11#charm-config-dns_domain, then just setting the A record pointing to the master to kubernetes.mydomain.com00:11
mbruzekoh yeah00:11
mbruzekThat00:11
bdxthe kubernetes charm will append the dns_name config to "kubernetes."00:12
mbruzekDo that then!00:12
bdxmbruzek: I did, but then I was still blocked by "unauthorized authority" error .... then I found the '--ssl-verify' option00:12
bdxwhich I set to false00:13
bdxand I now seem to be able to reach the endpoint successfully, but hit another trapped door :/00:14
bdxhttps://imgur.com/a/6IMya00:15
bdxmbruzek: thanks for your insight there00:19
catbus1stokachu: Hi, conjure-up imports ubuntu .root.tar.gz images for novakvm, shouldn't it be ubuntu -disk1.img?00:50
catbus1https://github.com/conjure-up/spells/blob/master/openstack-base/steps/share/glance.sh00:50
catbus1https://jujucharms.com/openstack-base/00:51
catbus1or is it the lxd images will work on kvm machines as well?00:52
=== ken is now known as Guest85087
=== ayan is now known as GoosGoarch
ElikseNNUDNO20:10

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!