Is root.crt and tls.crt certificate supposed to be the same?

40 views
Skip to first unread message

dan sun

unread,
Mar 25, 2020, 12:27:27 PM3/25/20
to cert-manager-dev
We are generating the self signed certificate with cert manager self signed issuer, in the secret generated looks the root.crt and tls.crt are both the same, but I believe that the TLS certificate should be generated by the cert manager using the CA certificate/key as the root of trust (see below). Is this expected?

apiVersion: v1
items:
- apiVersion: cert-manager.io/v1alpha2
  kind: Issuer
  metadata:
    name: selfsigned-issuer
    namespace: kfserving-system
  spec:
    selfSigned: {}
apiVersion: cert-manager.io/v1alpha2
kind: Certificate
metadata:
  name: serving-cert
  namespace: kfserving-system
spec:
  commonName: kfserving-webhook-server-service.kfserving-system.svc
  dnsNames:
  - kfserving-webhook-server-service.kfserving-system.svc
  issuerRef:
    kind: Issuer
    name: selfsigned-issuer
  secretName: kfserving-webhook-server-cert

kubectl get secrets -n kfserving-system kfserving-webhook-server-cert -o yaml
apiVersion: v1
data:
  ca.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURyekNDQXBlZ0F3SUJBZ0lRSzRiT05BUFBOaDdhNUhrTldDbkMrekFOQmdrcWhraUc5dzBCQVFzRkFEQlgKTVJVd0V3WURWUVFLRXd4alpYSjBMVzFoYm1GblpYSXhQakE4QmdOVkJBTVROV3RtYzJWeWRtbHVaeTEzWldKbwpiMjlyTFhObGNuWmxjaTF6WlhKMmFXTmxMbXRtYzJWeWRtbHVaeTF6ZVhOMFpXMHVjM1pqTUI0WERUSXdNRE15Ck5ERTROVEF4TTFvWERUSXdNRFl5TWpFNE5UQXhNMW93VnpFVk1CTUdBMVVFQ2hNTVkyVnlkQzF0WVc1aFoyVnkKTVQ0d1BBWURWUVFERXpWclpuTmxjblpwYm1jdGQyVmlhRzl2YXkxelpYSjJaWEl0YzJWeWRtbGpaUzVyWm5ObApjblpwYm1jdGMzbHpkR1Z0TG5OMll6Q0NBU0l3RFFZSktvWklodmNOQVFFQkJRQURnZ0VQQURDQ0FRb0NnZ0VCCkFPN0tRd1I1cWZrYVpoc3p0WDF1MVdyMm9mMmkvR1JPTlVvdWNzTDQraTYwODNOa3lqUnNEZVBQN0ZqVjFjbjEKYmZaWngvZWdjTUpRMXYxcE1MZjdlQkNubVlCWElXb09mYVVORzlVTzV4Z1p5dGlXSXg1NHAwcWRQVjdITXRCRQpwN09pbm1BM2dOOTczN3lsRTJhbVg2TjR0ZmhlK3hPdEpoS0ZYc2hudFUwZGdxMTdIMTBhbGxjYXlZS3E0aDA2CmN4VEN1MFFMNmFzL0VvNVdTRkI4d2F1TXVRU3NWZkhncXVDMkhoREcwdUlJOXFRZWR0MmpGZm4vL2M4dThJTUoKTGFMcjZnbStpekZqTGNnSzV0WE5ySDhtb3E3cHIzMGVZZm84Tm4zTERSd29SVDRYOGJEaUhSMGIzcHo3WTlVUwpHeXpPZWtEQTBTdlh3NVZpcE8wVDZ5RUNBd0VBQWFOM01IVXdEZ1lEVlIwUEFRSC9CQVFEQWdXZ01CTUdBMVVkCkpRUU1NQW9HQ0NzR0FRVUZCd01CTUF3R0ExVWRFd0VCL3dRQ01BQXdRQVlEVlIwUkJEa3dONEkxYTJaelpYSjIKYVc1bkxYZGxZbWh2YjJzdGMyVnlkbVZ5TFhObGNuWnBZMlV1YTJaelpYSjJhVzVuTFhONWMzUmxiUzV6ZG1NdwpEUVlKS29aSWh2Y05BUUVMQlFBRGdnRUJBTDVYMGYwR0llN1RPMEFwSFI0amZuT05jV0Q4dGh0c3VCSGhpN0JBCldYMXlzS0xodG40bnBsY0Y4dlRNQkNmS0ZiNk5KR1ZqUnI2VmJPRk5mSmNSbkJtM2FUdFFoZmNLZGxjYi94SUoKamFrSG9TL29uVTV0ME4rSmZ3TlNSWVNLaW9Fa3NsYUNkOEFLY2RpVkJCMjNXd1RrOUFEa09OYjR0ZlRwc3k0eApoM0J4MWs1WWtDWlNSS0pkVUhSdkhUL3JybnZiRFN4UXpiT1NIaWJabnhUY2tlOW9yY284VUNNMmFzRlNjVkNBCnpTSWZsMjNuSW5xZXNiS1FuWTZ5RWdwU2Q2TkVEODkzaTVhejhjTjlkeS9GSVFYSEg3S2EzZlY1SjM4OU5rVEUKUm1GWldHdzBmdzRLQXIyU3hLQUt0UHJISlNBMVRqQlJnTVI3ZnltOTRVbjhyc1k9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K
  tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURyekNDQXBlZ0F3SUJBZ0lRSzRiT05BUFBOaDdhNUhrTldDbkMrekFOQmdrcWhraUc5dzBCQVFzRkFEQlgKTVJVd0V3WURWUVFLRXd4alpYSjBMVzFoYm1GblpYSXhQakE4QmdOVkJBTVROV3RtYzJWeWRtbHVaeTEzWldKbwpiMjlyTFhObGNuWmxjaTF6WlhKMmFXTmxMbXRtYzJWeWRtbHVaeTF6ZVhOMFpXMHVjM1pqTUI0WERUSXdNRE15Ck5ERTROVEF4TTFvWERUSXdNRFl5TWpFNE5UQXhNMW93VnpFVk1CTUdBMVVFQ2hNTVkyVnlkQzF0WVc1aFoyVnkKTVQ0d1BBWURWUVFERXpWclpuTmxjblpwYm1jdGQyVmlhRzl2YXkxelpYSjJaWEl0YzJWeWRtbGpaUzVyWm5ObApjblpwYm1jdGMzbHpkR1Z0TG5OMll6Q0NBU0l3RFFZSktvWklodmNOQVFFQkJRQURnZ0VQQURDQ0FRb0NnZ0VCCkFPN0tRd1I1cWZrYVpoc3p0WDF1MVdyMm9mMmkvR1JPTlVvdWNzTDQraTYwODNOa3lqUnNEZVBQN0ZqVjFjbjEKYmZaWngvZWdjTUpRMXYxcE1MZjdlQkNubVlCWElXb09mYVVORzlVTzV4Z1p5dGlXSXg1NHAwcWRQVjdITXRCRQpwN09pbm1BM2dOOTczN3lsRTJhbVg2TjR0ZmhlK3hPdEpoS0ZYc2hudFUwZGdxMTdIMTBhbGxjYXlZS3E0aDA2CmN4VEN1MFFMNmFzL0VvNVdTRkI4d2F1TXVRU3NWZkhncXVDMkhoREcwdUlJOXFRZWR0MmpGZm4vL2M4dThJTUoKTGFMcjZnbStpekZqTGNnSzV0WE5ySDhtb3E3cHIzMGVZZm84Tm4zTERSd29SVDRYOGJEaUhSMGIzcHo3WTlVUwpHeXpPZWtEQTBTdlh3NVZpcE8wVDZ5RUNBd0VBQWFOM01IVXdEZ1lEVlIwUEFRSC9CQVFEQWdXZ01CTUdBMVVkCkpRUU1NQW9HQ0NzR0FRVUZCd01CTUF3R0ExVWRFd0VCL3dRQ01BQXdRQVlEVlIwUkJEa3dONEkxYTJaelpYSjIKYVc1bkxYZGxZbWh2YjJzdGMyVnlkbVZ5TFhObGNuWnBZMlV1YTJaelpYSjJhVzVuTFhONWMzUmxiUzV6ZG1NdwpEUVlKS29aSWh2Y05BUUVMQlFBRGdnRUJBTDVYMGYwR0llN1RPMEFwSFI0amZuT05jV0Q4dGh0c3VCSGhpN0JBCldYMXlzS0xodG40bnBsY0Y4dlRNQkNmS0ZiNk5KR1ZqUnI2VmJPRk5mSmNSbkJtM2FUdFFoZmNLZGxjYi94SUoKamFrSG9TL29uVTV0ME4rSmZ3TlNSWVNLaW9Fa3NsYUNkOEFLY2RpVkJCMjNXd1RrOUFEa09OYjR0ZlRwc3k0eApoM0J4MWs1WWtDWlNSS0pkVUhSdkhUL3JybnZiRFN4UXpiT1NIaWJabnhUY2tlOW9yY284VUNNMmFzRlNjVkNBCnpTSWZsMjNuSW5xZXNiS1FuWTZ5RWdwU2Q2TkVEODkzaTVhejhjTjlkeS9GSVFYSEg3S2EzZlY1SjM4OU5rVEUKUm1GWldHdzBmdzRLQXIyU3hLQUt0UHJISlNBMVRqQlJnTVI3ZnltOTRVbjhyc1k9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K
  tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQpNSUlFcFFJQkFBS0NBUUVBN3NwREJIbXArUnBtR3pPMWZXN1ZhdmFoL2FMOFpFNDFTaTV5d3ZqNkxyVHpjMlRLCk5Hd040OC9zV05YVnlmVnQ5bG5IOTZCd3dsRFcvV2t3dC90NEVLZVpnRmNoYWc1OXBRMGIxUTduR0JuSzJKWWoKSG5pblNwMDlYc2N5MEVTbnM2S2VZRGVBMzN2ZnZLVVRacVpmbzNpMStGNzdFNjBtRW9WZXlHZTFUUjJDclhzZgpYUnFXVnhySmdxcmlIVHB6Rk1LN1JBdnBxejhTamxaSVVIekJxNHk1Qkt4VjhlQ3E0TFllRU1iUzRnajJwQjUyCjNhTVYrZi85enk3d2d3a3RvdXZxQ2I2TE1XTXR5QXJtMWMyc2Z5YWlydW12ZlI1aCtqdzJmY3NOSENoRlBoZngKc09JZEhSdmVuUHRqMVJJYkxNNTZRTURSSzlmRGxXS2s3UlBySVFJREFRQUJBb0lCQURqQ2h5K1hJOW44ZG16YwoyN1VYRlUrNWxFUFA3Q0tEbkpNbmUwdnhGcmJuZUQ3anBGVFZvbStXU3QzSzVtaDlHRWhJaXduSGIwWWhKUmxUCldhdEI4UVkwY0g1Yk42d1lDYkdqN2d1MDRTV1BhL0lUcmdGZU9KVzV6bzZxMXQ4K2tvWldqMExicnB4d3Uzd0IKMlJ5N1MxeDJJdnNJeUxHaXBMd2VTNnRqUzJzcXRRVTQ0U0JEM2pPSDNGMEFwaGFvU2ZxSkV0K0VxSER1dTA4ZwpMYlRiUFJ6Zlh4SnVvTFpKd21uQkxXbVZzVUpJNG8xRWxhZkJtSWFVbUd4KzJodDRycVIwUEFqbzM2UG5oZHZMClR2SkR2eFJJb3lYazRwaEdDNGh1RzZZbFVXVjV2ei9SbjRoU3R0NDFiZjlEbWp5UG1GZ2l5a2h2RzVwYXU1NTgKVFFtaWtna0NnWUVBL05IWFBvdW9EWGJIS0dHQ0xLQW43VGkyb0VEMit4RXg1OGdTTHd6RmhoK0NEWkl0VG1sYgpKMmR5eGNTMmM1bWVvUEcvQUpHT2J5SnNMZHhZQmNiN0NZNHRldmhWNTloQURJSjRYUTNUYjNLeHdqOGVoZWQvCk41UzlwR3F6N0UvbTA4M3VrNXN2T1VPSjhmaS9hRlZXK3lOaTFSSWRxWWFseXNDV090MWMzVk1DZ1lFQThjczkKd1ZBWmx0ckZhbzVzdWJUNUFmdnhsM2dZY3cvY0lER1ZzWVVLSDVOVWhjQ1BXRys3YjhMMUVkblZYTUNqMW9oSQozZzFpREc1QTU5TXE4cFdlODFJZjhScDNEcjZMbGJLS0xZZm9tWWtYcEl0bXRwamRjNVZKNnFXSGVYNFVWbjZUCmFCd3JaS3c5NFdQQmo4STVNQU8zUTlmZytoRmF3cDBmazBjSlV6c0NnWUVBbG5yUUF3cGRIS1oySkRMbHFHb3IKV2FkSURGcWVweEcxQXFDek1nNElBNno5VzlhRjRRWVVtMytYY04rRk9ZbFdRYldpV2xSSTB4MUtCb0lBWW0vdApPK0xFYjAwZzFMNkNZTy9IZEp1bUhjL0d2amVUazJBVytKNHZ3bzFBU29mRWZJMDJVK1VxVm9zOHNDbSt3L3NICnFyT0ZRQTFvV2w4cWoyUFNCM2Q2cnNFQ2dZRUExcFNwRkpMeWNyZHFOZHQ1MEFFMGJ6ZFpPelJBZG5TZnhRNWMKSzdQR3ZTangvTlZjSVg3ZkdCc3JoSkVPVWdkQUgxYkpYQThDY2NleTRFbStOcFRrQUVwa3dJTGRILytvUHN5NAo1aGxVS2xYSTNxVThIVlppU1g0Mm9BQVF6NWc5a2xrNGxrOVJqMEZ3bFVNRGQ0SkZZRUFiOXlCeHIxdVJjVjhoCnM0RjZYQnNDZ1lFQXQ5bDdKN3BuNG0rNHRrYlV3bCtmRHZpT2xpQmt5bDlCUFhSOHkxbjl4eFd6anZpMU8yRGUKSDRDaW5qWktEcWthbkpJRTNQS2FPVGFib21RaUU0TnNDQVlwN0Q3cGdrTHRDVXRKVzFGRmw4ODJGWnRkUHlHRQpzM3RGSVpjcFFjMTlTRXdZQ0h4bW9KYUV2UGFKYnM3a1BXb282dEpCQ3pSTXlBdldHQlNSQnM0PQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQo=
Reply all
Reply to author
Forward
0 new messages