基于Rancher 部署docker集群
time="2019-11-14T22:47:24Z" level=info msg="SignatureAlgorithm: SHA256-RSA"
time="2019-11-14T22:47:24Z" level=info msg="PublicKeyAlgorithm: RSA"
time="2019-11-14T22:47:24Z" level=info msg="Certificate details for /etc/kubernetes/ssl/certs/serverca"
time="2019-11-14T22:47:24Z" level=info msg="Certificate #0 (/etc/kubernetes/ssl/certs/serverca)"
time="2019-11-14T22:47:24Z" level=info msg="Subject: CN=cattle-ca,O=the-ranch"
time="2019-11-14T22:47:24Z" level=info msg="Issuer: CN=cattle-ca,O=the-ranch"
time="2019-11-14T22:47:24Z" level=info msg="IsCA: true"
time="2019-11-14T22:47:24Z" level=info msg="DNS Names: <none>"
time="2019-11-14T22:47:24Z" level=info msg="IPAddresses: <none>"
time="2019-11-14T22:47:24Z" level=info msg="NotBefore: 2019-11-15 06:09:02 +0000 UTC"
time="2019-11-14T22:47:24Z" level=info msg="NotAfter: 2029-11-12 06:09:02 +0000 UTC"
time="2019-11-14T22:47:24Z" level=info msg="SignatureAlgorithm: SHA256-RSA"
time="2019-11-14T22:47:24Z" level=info msg="PublicKeyAlgorithm: RSA"
time="2019-11-14T22:47:24Z" level=fatal msg="Server certificate is not valid, please check if the host has the correct time configured and if the server certificate has a notAfter date and time in the future. Certificate information is displayed above.
error: Get https://172.16.66.3: x509: certificate has expired or is not yet valid"
解决办法:
这个问题基本上是因为证书出现过期导致,查看虚拟机和远程服务器的时间是否同步:
date
- 如果时间不一致,则执行:
ntpdate cn.pool.ntp.org