码迷,mamicode.com
首页 > 其他好文 > 详细

申请ca证书

时间:2021-04-10 13:02:49      阅读:0      评论:0      收藏:0      [点我收藏+]

标签:hal   code   following   client   unit   ali   roo   export   ssl   

# 生成CA证书
openssl genrsa -out ca/ca-key.pem 2048
openssl req -new -out ca/ca-req.csr -key ca/ca-key.pem
-----
Country Name (2 letter code) [AU]:cn
State or Province Name (full name) [Some-State]:guangdong
Locality Name (eg, city) []:shenzhen
Organization Name (eg, company) [Internet Widgits Pty Ltd]:jxk
Organizational Unit Name (eg, section) []:jxk
Common Name (e.g. server FQDN or YOUR name) []:root
Email Address []:test

Please enter the following extra attributes
to be sent with your certificate request
A challenge password []:123456
An optional company name []:123456


openssl x509 -req -in ca/ca-req.csr -out ca/ca-cert.pem -signkey ca/ca-key.pem -days 3650
openssl pkcs12 -export -clcerts -in ca/ca-cert.pem -inkey ca/ca-key.pem -out ca/ca.p12

# 生成server证书
openssl genrsa -out server/server-key.pem 2048
openssl req -new -out server/server-req.csr -key server/server-key.pem

-----
Country Name (2 letter code) [AU]:cn
State or Province Name (full name) [Some-State]:guangdong
Locality Name (eg, city) []:shenzhen
Organization Name (eg, company) [Internet Widgits Pty Ltd]:jxk
Organizational Unit Name (eg, section) []:jxk
Common Name (e.g. server FQDN or YOUR name) []:127.0.0.1
Email Address []:test

Please enter the following extra attributes
to be sent with your certificate request
A challenge password []:123456
An optional company name []:123456

 

openssl x509 -req -in server/server-req.csr -out server/server-cert.pem -signkey server/server-key.pem -CA ca/ca-cert.pem -CAkey ca/ca-key.pem -CAcreateserial -days 3650
openssl pkcs12 -export -clcerts -in server/server-cert.pem -inkey server/server-key.pem -out server/server.p12

 

# 生成client证书
openssl genrsa -out client/client-key.pem 2048
openssl req -new -out client/client-req.csr -key client/client-key.pem

-----
Country Name (2 letter code) [AU]:cn
State or Province Name (full name) [Some-State]:guangdong
Locality Name (eg, city) []:shenzhen
Organization Name (eg, company) [Internet Widgits Pty Ltd]:jxk
Organizational Unit Name (eg, section) []:jxk
Common Name (e.g. server FQDN or YOUR name) []:root
Email Address []:test

Please enter the following extra attributes
to be sent with your certificate request
A challenge password []:123456
An optional company name []:123456


openssl x509 -req -in client/client-req.csr -out client/client-cert.pem -signkey client/client-key.pem -CA ca/ca-cert.pem -CAkey ca/ca-key.pem -CAcreateserial -days 3650
openssl pkcs12 -export -clcerts -in client/client-cert.pem -inkey client/client-key.pem -out client/client.p12

 

申请ca证书

标签:hal   code   following   client   unit   ali   roo   export   ssl   

原文地址:https://www.cnblogs.com/jxkshu/p/ca.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!