[req] default_bits = 4096 prompt = no encrypt_key = no default_md = sha256 distinguished_name = kubelet_serving req_extensions = v3_req x509_extensions = v3_req [ kubelet_serving ] O = system:nodes CN = system:node [ v3_req ] basicConstraints = CA:FALSE keyUsage = nonRepudiation, digitalSignature, keyEncipherment, dataEncipherment extendedKeyUsage = serverAuth, clientAuth subjectAltName = @alt_names [alt_names] IP.1 = 127.0.0.1 DNS.1 = vault-1 DNS.2 = vault-2 DNS.3 = vault-3