Specify subject name when generating keypair #13817
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This is primarily for microcluster. From the discussions in Madrid about join token verification (the MITM discussions), we decided we would verify that the SAN of the
server.crt
of a joiner microcluster node must match the node name specified when creating the join token.By default, LXD sets this to be the hostname of the system that generated the certificate. In microcluster, the node name does not necessarily always have to line up exactly with the hostname of the system, rather the name is supplied at the time we bootstrap or join a cluster. So we need to be able to set the name in the certificate ourselves.