change(docker): use step-ca for CA + cert generation

Signed-off-by: Kevin Morris <kevr@0cost.org>
This commit is contained in:
Kevin Morris 2021-11-27 16:43:29 -08:00
parent e558e979ff
commit b98159d5b9
No known key found for this signature in database
GPG key ID: F7E46DED420788F3
10 changed files with 160 additions and 69 deletions

View file

@ -0,0 +1,19 @@
#!/usr/bin/env python3
import json
import sys
CA_CONFIG = sys.argv[1]
with open(CA_CONFIG) as f:
data = json.load(f)
if "authority" not in data:
data["authority"] = dict()
if "claims" not in data["authority"]:
data["authority"]["claims"] = dict()
# One year of certificate duration.
data["authority"]["claims"] = {"maxTLSCertDuration": "8800h"}
with open(CA_CONFIG, "w") as f:
json.dump(data, f)