Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Generate ssl (https) certificates using openssl

Shulou Source: shulou.com Published: 2022-06-01 04:03:52 10月06日 Update

Openssl generates certificates

[nginx@machina key] $pwd

/ app/nginx/key

Generate a private key

Openssl genrsa-out server.key 2048 generates a certificate request

Openssl req-new-key server.key-out server.csr fill in the information [nginx@machina key] $openssl req-new-key server.key-out server.csrYou are about to be asked to enter information that will be incorporatedinto your certificate request.What you are about to enter is what is called a Distinguished Name ora DN.There are quite a few fields but you can leave some blankFor some fields there will be a default value,If you enter'. The field will be left blank.-Country Name (2 letter code) [XX]: cnState or Province Name (full name) []: gdLocality Name (eg, city) [Default City]: gzOrganization Name (eg, company) [Default Company Ltd]: aiOrganizational Unit Name (eg, section) []: aiCommon Name (eg, your name or your server's hostname) []: 112.96.28.206Email Address []:

Please enter the following 'extra' attributes

To be sent with your certificate request

A challenge password []:

An optional company name []:

[nginx@machina key] $

[nginx@machina key] $ls

Old server.csr server.key

4. Back up a server key file cp server.key server.key.org5. Remove the file password openssl rsa-in server.key.org-out server.key6. Generate certificate file server.crtopenssl x509-req-days 365-in server.csr-signkey server.key-out server.crt

[nginx@machina key] $openssl rsa-in server.key.org-out server.key

Writing RSA key

[nginx@machina key] $

[nginx@machina key] $openssl x509-req-days 365-in server.csr-signkey server.key-out server.crt

Signature ok

Subject=/C=cn/ST=gd/L=gz/O=ai/OU=ai/CN=112.96.28.206

Getting Private key

Generally speaking, it only takes three steps: 1. Openssl genrsa-out server.key 20482. Openssl req-new-key server.key-out server.csr3. Openssl x509-req-days 365-in server.csr-signkey server.key-out server.crt about the password: openssl genrsa-out server.key 2048 does not need a password. Openssl genrsa-des3-out server.key 2048 requires a password. Https://www.jianshu.com/p/9523d888cf77 about domain name: use openssl, domain name can not be lost; with keystore, you must enter.

Tags: Generate certificate password file domain name information password just backup key server service input Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Tech Info MariaDB MySQL Apple Xiaomi