安全性-无法使用gRPC创建安全的TLS连接

时间:2019-05-22 12:30:42

标签: go kubernetes grpc istio knative

我需要与Knative的安全连接。

尝试了一个百万富翁,并在我的头顶上,出现以下情况:

WORKED:
|----------------------------------------------------------------------------|--------------------------------------------|
| 1. curl -H "Host:  my-servivce.default.mydomin.com" http(s)://mydomain.com | knative-ingress-gateway(tls with cert.pem) |
|----------------------------------------------------------------------------|--------------------------------------------|
| 2. unsecure gRPC port:80                                                   | knative                                    |
|----------------------------------------------------------------------------|--------------------------------------------|

NOT WORKING:
|-----------------------------|------------------------------------------------------------------------------------------------|
| 3. unsecure gRPC port:443   | knative-ingress-gateway(tls PASSTHROUGH)                                                       |
|-----------------------------|------------------------------------------------------------------------------------------------|
| 4.     --//--               | knative-ingress-gateway(tls with cert.pem) using same working certificate as for 1. (curl)     |
|-----------------------------|--------------------------------------------|---------------------------------------------------|
| 5. secure gRPC(cert from 4.)| knative-ingress-gateway(tls PASSTHROUGH)   | gRPC secure server OpenSSL mydomain.com           |
|-----------------------------|--------------------------------------------|---------------------------------------------------|    
| 6. OpenSSL secure gRPC      | knative-ingress-gateway(tls PASSTHROUGH)   | gRPC secure server OpenSSL mydomain.com           |
|-----------------------------|--------------------------------------------|---------------------------------------------------|
| 7.     --//--               | knative-ingress-gateway(tls PASSTHROUGH)   | gRPC secure server OpenSSL internall host domain  |
|--------------------------   |--------------------------------------------|---------------------------------------------------|

如果您可以使用TLS或http进行任何操作,或者知道使用它的人,我非常想知道吗?

预先感谢

0 个答案:

没有答案