Checking PostgreSQL cluster certificates¶
During installation, during a renewal, or simply to find out when the PostgreSQL cluster certificates expire, it can be useful to examine the content of the generated certificates.
The certificates used by the PostgreSQL cluster are the following:
1 2 3 4 5 6 7 8 9 10 11 | |
ca.crt-
Certificate of the root certification authority. The same certificate is present in the
/etc/patroni/and/etc/etcd/directories. client.crt-
Certificate of the PostgreSQL node. The same certificate is present in the
/etc/patroni/and/etc/etcd/directories. It is used bypatroniandetcdfor client communications between the nodes. client.key-
Key associated with the
client.crtcertificate. peer.crt-
Same certificate as
client.crt. It is used for the internaletcdcommunications between the nodes. peer.key-
Same key as
client.key.
There are therefore three items in all:
- the certificate of the root certification authority (
/etc/etcd/ca.crt,/etc/patroni/ca.crt); - the certificate of the PostgreSQL node (
/etc/etcd/client.crt,/etc/etcd/peer.crt,/etc/patroni/client.crt); - the key associated with the certificate of the PostgreSQL node (
/etc/etcd/client.key,/etc/etcd/peer.key,/etc/patroni/client.key).
Checking the expiration date of a certificate¶
To check the expiration date of a certificate, use the command below.
You can customize the variable for the following command:
| Custom value | Variable | Comment |
|---|---|---|
EXPIRY_CERT |
Path of the certificate whose expiration date to check. |
Or fill the field with one of the cluster certificates:
1 | |
If the expiration date has passed, the certificate is considered invalid.
Warning
If the certification authority that issued the certificate has expired, the certificate is also considered invalid. Therefore also check the expiration date of the certification authority.
Example
To check the expiration date of the /etc/patroni/client.crt certificate, we use the following command:
1 | |
The output is similar to this one:
1 | |
Here, the certificate expires on December 18, 2030 at 14:04:09.
Checking the Subject Alternative Names of a certificate¶
To check the SANs (Subject Alternative Names) of a certificate, that is, the names and IP addresses for which it is valid, use the command below.
You can customize the variable for the following command:
| Custom value | Variable | Comment |
|---|---|---|
SAN_CERT |
Path of the certificate whose SANs to check. |
Or fill the field with one of the node certificates:
1 | |
If the DNS name or IP address used to connect to a node is not in the SANs of its certificate, the connection is considered invalid. Likewise, when a node opens a connection to another node, if the certificate it presents does not match its own DNS name or IP address, the remote node rejects the connection.
Example
To check the SANs of the /etc/etcd/peer.crt certificate, we use the following command:
1 | |
The command returns a result similar to this one:
1 2 | |
Here, the certificate covers the DNS names PSQL_VIP and PSQL_2, as well as the IP addresses 192.168.1.4 and 192.168.1.2.
Checking which certification authority issued a certificate¶
When a certificate is generated, the X509v3 Authority Key Identifier extension can be added to it. This extension can store the hash of its issuer's public key, which matches the content of the issuer's X509v3 Subject Key Identifier extension.
Info
Certificates generated by following the PostgreSQL cluster installation documentation have the Authority Key Identifier and Subject Key Identifier extensions.
If these extensions are present, you can retrieve the hash of the public key of a certificate's issuer, then compare it with the hash in the Subject Key Identifier extension of the CA that is supposed to have issued the certificate, to confirm that it is the right one.
To retrieve the value of the Authority Key Identifier extension of a certificate, use the command below.
You can customize the variable for the following command:
| Custom value | Variable | Comment |
|---|---|---|
ISSUED_CERT |
Path of the certificate whose issuer to check. |
Or fill the field with one of the node certificates:
1 | |
Info
The -issuer option retrieves the CN of the issuing certificate.
To retrieve the value of the Subject Key Identifier extension of a certificate, use the command below.
You can customize the variable for the following command:
| Custom value | Variable | Comment |
|---|---|---|
ISSUER_CA |
Path of the certificate of the certification authority assumed to be the issuer. |
Or fill the field with one of the certification authority certificates:
1 | |
Info
The -subject option retrieves the CN of the certificate.
Example
We want to check that the CA that signed the certificate in the /etc/patroni/client.crt file is indeed the one in the /etc/patroni/ca.crt file.
We first retrieve the content of the X509v3 Authority Key Identifier extension of the /etc/patroni/client.crt certificate with the following command:
1 | |
Which returns:
1 2 3 | |
We then retrieve the content of the X509v3 Subject Key Identifier extension of the /etc/patroni/ca.crt CA with the following command:
1 | |
Which returns:
1 2 3 | |
Comparing the two outputs shows that the Key Identifier and the CN are identical: the certificate in the /etc/patroni/ca.crt file is indeed the CA that signed the certificate in the /etc/patroni/client.crt file.