您好,登錄后才能下訂單哦!
1、自建CA
# cd /etc/pki/CA/ # (umask 077; openssl genrsa -out private/cakey.pem 2048) # openssl req -new -x509 -key private/cakey.pem -out cacert.pem -days 3656 Country Name (2 letter code) [XX]:CN State or Province Name (full name) []:Yunnan Locality Name (eg, city) [Default City]:Kunming Organization Name (eg, company) [Default Company Ltd]:San Organizational Unit Name (eg, section) []:Students Common Name (eg, your name or your server's hostname) []:ca.san.com Email Address []:caadmin@san.com # ls -lh 總用量 20K -rw-r--r--. 1 root root 1.4K 3月 29 16:18 cacert.pem # touch serial index.txt serial # echo 01 > serial # ls cacert.pem certs crl index.txt newcerts private serial
2、證書簽署
# (umask 077; openssl genrsa -out /root/mykey2.pri 2048) #生成一個私鑰 # openssl req -new -key /root/mykey2.pri -out /root/myreq.csr #生成證書 Country Name (2 letter code) [XX]:CN State or Province Name (full name) []:Yunnan Locality Name (eg, city) [Default City]:Kunming Organization Name (eg, company) [Default Company Ltd]:San Organizational Unit Name (eg, section) []:Students Common Name (eg, your name or your server's hostname) []:www.san.com Email Address []:admin@san.com Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []: # openssl ca -in myreq.csr -out mycert.crt -days 365簽署證書 # ls mycert.crt #證書簽署完成
免責聲明:本站發布的內容(圖片、視頻和文字)以原創、轉載和分享為主,文章觀點不代表本網站立場,如果涉及侵權請聯系站長郵箱:is@yisu.com進行舉報,并提供相關證據,一經查實,將立刻刪除涉嫌侵權內容。