diff --git a/docs/book/src/tasks/certs/generate-kubeconfig.md b/docs/book/src/tasks/certs/generate-kubeconfig.md index 67a4e707b6d5..b9e9714a644b 100644 --- a/docs/book/src/tasks/certs/generate-kubeconfig.md +++ b/docs/book/src/tasks/certs/generate-kubeconfig.md @@ -1,9 +1,9 @@ ## Generating a Kubeconfig with your own CA -1. Create a new Certificate Signing Request (CSR) for the `system:masters` Kubernetes role, or specify any other role under CN. +1. Create a new Certificate Signing Request (CSR) for the `admin` user with the `system:masters` Kubernetes role, or specify any other role under O. ```bash - openssl req -subj "/CN=system:masters" -new -newkey rsa:2048 -nodes -out admin.csr -keyout admin.key -out admin.csr + openssl req -subj "/CN=admin/O=system:masters" -new -newkey rsa:2048 -nodes -keyout admin.key -out admin.csr ``` 2. Sign the CSR using the *[cluster-name]-ca* key: