Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Configure private CA commands and configure certificates

Shulou Source: shulou.com Published: 2022-06-01 06:54:41 10月03日 Update

One: configure private CA commands

1. Edit configuration file / etc/pki/tls/openssl.cnf

Change dir to change ".. / CA" to "/ etc/pki/CA"

You can change the default country, province, and city

Mkdir certs newcerts crl

Touch index.txt

Touch serial

Echo 01 > serial

two。 Create a private key (from which the public key is generated)

Under the / etc/pki/CA directory

(umask 077 position OpenSSL genrsa 2048 > private/cakey.pem) or

(umask 07710 OpenSSL genrsa-out private/cakey.pem 2048)

Note: the-out option should be immediately followed by genrsa

Openssl rsa-in server.key-pubout extract public key

3. Generate a certificate

Openssl req-new-x509-key private/cakey.pem-out cacert.pem

Note:-new: generate a new certificate

-x509: certificate format (required to generate CA self-signed certificate)

Openssl x509-text-in server.crt (view certificate format)

Two: configure the certificate

1. Generate secret key

(umask 07710 OpenSSL genrsa-out ssl/httpd.key 1024)

two。 Generate a certificate

Openssl req-new-key httpd.key-out httpd.csr

3. Give it to CA for signature

Openssl ca-in httpd.csr-out httpd.crt-days 365

Tags: Certificate generation configuration public key format comment command private country city file directory province visa Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno NVidia Shulou Technology Linux vpn Redmi