This topic explains how to create self-signed TLS certificates for use in an
environment configuration. This information is intended for trial or testing
purposes only.
The runtime ingress gateway (the gateway that handles API proxy traffic) requires
a TLS certificate/key pair. For this quickstart installation, you can use self-signed
credentials. In the following steps, openssl is used
to generate the credentials.
Execute the following command to create the certificate and key files. The certificate files
will most likely have .crt or .pem extensions and the key file will most likely
have .key.
This command creates a self-signed certificate/key pair that you can use for the
quickstart installation. The CN mydomain.net can be any value you wish for
the self-signed credentials.
Check to make sure the files are in the ./certs directory:
ls ./certs
keystore.pem
keystore.key
Where keystore.pem is the self-signed TLS certificate file and keystore.key
is the key file.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-03-07 UTC."],[[["This document explains how to create self-signed TLS certificates for trial or testing environments, which are not recommended for production use."],["The runtime ingress gateway requires a TLS certificate/key pair, and self-signed credentials can be used for quickstart installations."],["The `openssl` command is used to generate self-signed certificate and key files, which should preferably be stored in the `hybrid-files/certs` directory if using `apigeectl`."],["A sample `openssl` command is provided to generate the certificate/key pair, with the ability to customize the Common Name (CN) value, and it will create two files, `keystore.pem` (certificate) and `keystore.key` (key)."]]],[]]