website
website copied to clipboard
Missing page that explain how to migrate an existing cluster to use TLS for peer and/or client communications
There are intructions on how bootstrap a new cluster with TLS capabilities, but none that explains how an existing running cluster could be hardened to use TLS security for peers, clients or both.
Simply providing the TLS files (cert, private key and CA cert) and changing the urls from http to https doesn't work: the result will be a lot of tls: first record does not look like a TLS handshake
errors.