Fix several istio.io tasks. (#5539)

This commit is contained in:
Oliver Liu 2019-11-09 06:32:00 -08:00 committed by Istio Automation
parent f46ad5fe89
commit 98ce605cb8
1 changed files with 3 additions and 2 deletions

View File

@ -106,7 +106,7 @@ This requires you have `openssl` installed on your machine.
1. Verify the CA certificate is the same as the one specified by operator:
{{< text bash >}}
$ tail -n 23 /tmp/pod-cert-chain.pem > /tmp/pod-cert-chain-ca.pem
$ sed '0,/^-----END CERTIFICATE-----/d' /tmp/pod-cert-chain.pem > /tmp/pod-cert-chain-ca.pem
$ openssl x509 -in @samples/certs/ca-cert.pem@ -text -noout > /tmp/ca-cert.crt.txt
$ openssl x509 -in /tmp/pod-cert-chain-ca.pem -text -noout > /tmp/pod-cert-chain-ca.crt.txt
$ diff /tmp/ca-cert.crt.txt /tmp/pod-cert-chain-ca.crt.txt
@ -124,10 +124,11 @@ This requires you have `openssl` installed on your machine.
## Cleanup
* To remove the secret `cacerts`:
* To remove the secret `cacerts` and redeploy Citadel with self-signed root certificate:
{{< text bash >}}
$ kubectl delete secret cacerts -n istio-system
$ istioctl manifest apply --set values.global.mtls.enabled=true --set values.global.controlPlaneSecurityEnabled=true
{{< /text >}}
* To remove the Istio components: follow the [uninstall instructions](/docs/setup/install/kubernetes/#uninstall) to remove.