VIP:192.168.0.10
DIP:192.168.0.61
RIP1:192.168.0.62
RIP2:192.168.0.63
为了简单起见,先使用同网段架设LVS服务。
预先安装好http和htpps服务:
RS1:
# yum install mod_ssl
# cd /etc/httpd/conf
# mkdir ssl
# (umask 077;openssl genrsa 1024 > httpd.key)
# openssl req -new -key httpd.key -out httpd.csr
Country Name (2 letter code) [XX]:CN
State or Province Name (full name) []:BJ
Locality Name (eg, city) [Default City]:BJ
Organization Name (eg, company) [Default Company Ltd]:Tech
Organizational Unit Name (eg, section) []:test.glx.com
Common Name (eg, your name or your server's hostname) []:
Email Address []:
申请证书生成完毕,发送给自建CA进行证书签署
Country Name (2 letter code) [XX]:CN
State or Province Name (full name) []:BJ
Locality Name (eg, city) [Default City]:BJ
Organization Name (eg, company) [Default Company Ltd]:Tech
Organizational Unit Name (eg, section) []:test.glx.com
Common Name (eg, your name or your server's hostname) []:
Email Address []:
# touch index.txt
# echo 01 > serial
签署证书:
# openssl ca -in httpd.csr -out httpd.crt -days 365
将签署完毕的证书分别发送给RS1