You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Kubernetes中为部署的服务生成EV SSL证书CSR

生成适用于Kubernetes服务的EV SSL证书签名请求(CSR)

Got it, let's walk through exactly how to generate an EV SSL CSR for your Kubernetes service and get it set up properly. EV certs have stricter identity requirements, so we need to make sure every step is on point:

1. 生成加密私钥

First, generate a strong private key (EV certs typically recommend 4096-bit for better security). Run this command on your local machine or a secure server (never commit this key to version control):

openssl genrsa -out my-ev-service.key 4096

2. 创建符合EV要求的CSR

EV certificates require detailed organizational information that the CA will verify thoroughly. You can generate the CSR either interactively or via a non-interactive command (the latter avoids typos).

非交互式生成(推荐)

Use the -subj flag to specify all required fields. Replace the values with your actual organization and domain details:

openssl req -new -key my-ev-service.key -out my-ev-service.csr -sha256 -subj "/C=CN/ST=Shanghai/L=Shanghai/O=Your Full Registered Company Name/OU=Your Department Name/CN=your-service.example.com"

Let's break down the mandatory fields:

  • C: 2-letter country code (e.g., CN for China, US for United States)
  • ST: Full state/province name (no abbreviations)
  • L: Full city name
  • O: Your company's exact registered legal name (must match official documents like business license)
  • CN: The primary domain for your Kubernetes service (e.g., api.yourcompany.com)

多域名(SAN)EV CSR

If you need to cover multiple domains (like your main service domain and a subdomain), create a config file first (name it ev-csr.conf):

[req]
default_bits = 4096
prompt = no
default_md = sha256
distinguished_name = dn
req_extensions = req_ext

[dn]
C=CN
ST=Shanghai
L=Shanghai
O=Your Full Registered Company Name
OU=Engineering
CN=api.yourcompany.com

[req_ext]
subjectAltName = @alt_names

[alt_names]
DNS.1 = api.yourcompany.com
DNS.2 = admin.yourcompany.com

Then generate the CSR using this config:

openssl req -new -key my-ev-service.key -out my-ev-service.csr -config ev-csr.conf

3. 提交CSR给EV证书颁发机构

Submit the my-ev-service.csr file to your chosen CA. They will initiate an extensive verification process for EV certs—this includes validating your company's legal existence, domain ownership, and that you're authorized to request the cert. Prepare documents like:

  • Business registration certificate (e.g., company license)
  • Domain ownership proof (e.g., DNS TXT record, WHOIS verification)
  • Authorization letter if you're not the company's legal representative

4. 在Kubernetes中部署EV证书

Once the CA approves and sends you the final certificate files (usually a primary .crt file and intermediate certs), you'll need to store them in a Kubernetes Secret:

合并证书链(如果需要)

Some CAs send separate intermediate certs. Combine your primary cert with the intermediates into a single file to ensure proper trust chain validation:

cat my-ev-service.crt intermediate.crt > fullchain.crt

创建TLS Secret

Run this command to create a secret that holds your cert and private key:

kubectl create secret tls ev-service-tls --cert=fullchain.crt --key=my-ev-service.key

引用Secret in Ingress/Service

Finally, update your Kubernetes Ingress resource to use the EV cert. Here's an example Ingress YAML:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: my-service-ingress
  annotations:
    nginx.ingress.kubernetes.io/ssl-redirect: "true"
spec:
  tls:
  - hosts:
    - api.yourcompany.com
    - admin.yourcompany.com
    secretName: ev-service-tls
  rules:
  - host: api.yourcompany.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: your-k8s-service
            port:
              number: 80

关键注意事项

  • Secure your private key: Keep it in a safe, encrypted location—if it's compromised, your EV cert loses its trust status.
  • Verify CA requirements: Some CAs may have specific CSR formatting rules (e.g., hash algorithm, key size), so double-check their docs before generating.
  • Test after deployment: Use tools like openssl s_client -connect your-service.example.com:443 to confirm the EV cert is being served correctly and the trust chain is intact.

内容的提问来源于stack exchange,提问作者Janny K.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 03:29:48