AI-VAULT证书导入前,无法访问其它接口,需要在部署AI-VAULT前导入证书。
AI-VAULT组件提供证书申请请求和导入证书请求命令行接口。
用户按照如下操作完成证书配置。
cd /home/AiVault mkdir aivault chmod 700 /home/AiVault/aivault cd /home/AiVault/aivault unzip Ascend-mindxdl-aivault_{version}_linux-{arch}.zip tar --no-same-owner --no-same-permission -zxf Ascend-mindxdl-aivault_{version}_linux-{arch}.tar.gz
export LD_LIBRARY_PATH=/home/AiVault/aivault/lib /home/AiVault/aivault/ai-vault req -type MGMT -subject "CN|SiChuan|ChengDu|Huawei|Ascend" /home/AiVault/aivault/ai-vault req -type SVC -subject "CN|SiChuan|ChengDu|Huawei|Ascend"
csr文件路径说明:
chmod 400 rsa.trust.pem chmod 400 rsa.SVC.pem chmod 400 rsa.MGMT.pem
cd /home/AiVault/cert_tmp /home/AiVault/aivault/ai-vault x509 -type MGMT -caFile rsa.trust.pem -certFile rsa.MGMT.pem /home/AiVault/aivault/ai-vault x509 -type SVC -caFile rsa.trust.pem -certFile rsa.SVC.pem
如需添加证书吊销列表, 可在导入命令中使用参数“-crlFile”补充吊销列表路径,如:-crlFile cert.crl。
导入证书执行完后 请及时删除“cert_tmp”目录。
rm -rf /home/AiVault/cert_tmp