openssl req -new -key  kubelet.key -out kubelet-client.csr -subj "/CN=system:node:master2/O=system:nodes"
openssl x509 -req -in kubelet-client.csr -CA /etc/kubernetes/pki/ca.crt  -CAkey /etc/kubernetes/pki/ca.key  -CAcreateserial -out kubelet-client.crt -days 36500
rm -f kubelet-client-current.pem.new 
cat kubelet-client.crt kubelet.key >>  kubelet-client-current.pem.new
rm -f kubelet-client-current.pem
ln -s kubelet-client-current.pem.new kubelet-client-current.pem