标签:window import https ssl ebe comm 验证 输入 net
目录
genrsa -out ca/ca-key.pem 1024
req -new -out ca/ca-req.csr -key ca/ca-key.pem
x509 -req -in ca/ca-req.csr -out ca/ca-cert.pem -signkey ca/ca-key.pem -days 3650
pkcs12 -export -clcerts -in ca/ca-cert.pem -inkey ca/ca-key.pem -out ca/ca.p12
tips : common name 填 写 本 地 IP 地 址 !【图中箭头部分】
genrsa -out server/server-key.pem 1024
req -new -out server/server-req.csr -key server/server-key.pem
x509 -req -in server/server-req.csr -out server/server-cert.pem -signkey server/server-key.pem -CA ca/ca-cert.pem -CAkey ca/ca-key.pem -CAcreateserial -days 3650
pkcs12 -export -clcerts -in server/server-cert.pem -inkey server/server-key.pem -out server/server.p12
genrsa -out client/client-key.pem 102
req -new -out client/client-req.csr -key client/client-key.pem
x509 -req -in client/client-req.csr -out client/client-cert.pem -signkey client/client-key.pem -CA ca/ca-cert.pem -CAkey ca/ca-key.pem -CAcreateserial -days 3650
pkcs12 -export -clcerts -in client/client-cert.pem -inkey client/client-key.pem -out client/client.p12
tips : 换!路!径!【jdk的bin目录下输入命令】
keytool -keystore C:\OpenSSL-Win64\bin\jks\truststore.jks -keypass 222222 -storepass 222222 -alias ca -import -trustcacerts -file C:\OpenSSL-Win64\bin\ca\ca-cert.pem
<Connector port="8443" protocol="HTTP/1.1" SSLEnabled="true"
maxThreads="150" scheme="https" secure="true"
clientAuth="true" sslProtocol="TLS"
keystoreFile="C:\OpenSSL-Win64\bin\server\server.p12" keystorePass="changeit" keystoreType="PKCS12"
truststoreFile="C:\OpenSSL-Win64\bin\jks\truststore.jks" truststorePass="222222" truststoreType="JKS"/>
Windows下使用OpenSSL生成自签证书
CA认证过程及https实现方法之Linux
标签:window import https ssl ebe comm 验证 输入 net
原文地址:https://www.cnblogs.com/poziiey/p/12491214.html