User Tools

Site Tools


ssl:generate-certificates-self-signed

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
ssl:generate-certificates-self-signed [2020/08/08 18:45]
odefta
ssl:generate-certificates-self-signed [2020/08/08 20:58] (current)
odefta
Line 123: Line 123:
 An optional company name []: An optional company name []:
 </code> </code>
 +
 +===== Create extension file (ssl.conf) =====
 +
 +<file ini ssl.conf>
 +[ req ]
 +default_bits       = 2048
 +distinguished_name = req_distinguished_name
 +req_extensions     = req_ext
 +
 +[ req_distinguished_name ]
 +countryName                 = RO
 +countryName_default         = RO
 +stateOrProvinceName         = Romania
 +stateOrProvinceName_default = Romania
 +localityName                = Bucharest
 +localityName_default        = Bucharest
 +organizationName            = AX
 +organizationName_default    = AX
 +commonName                  = item-ax32034
 +commonName_max              = 64
 +commonName_default          = localhost
 +
 +[ req_ext ]
 +subjectAltName = @alt_names
 +
 +[alt_names]
 +DNS.1   = item-ax
 +DNS.2   = item-ax.com
 +</file>
  
 ===== Generate the actual certificate (int1.crt) singed by the Root CA (ca.crt) ===== ===== Generate the actual certificate (int1.crt) singed by the Root CA (ca.crt) =====
  
 <code> <code>
-openssl x509 -req -in int1.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out int1.crt -days 1000 -sha256+openssl x509 -req -in int1.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out int1.crt -days 1000 -sha256 -extensions req_ext -extfile ssl.conf
 </code> </code>
  
Line 133: Line 162:
 <code> <code>
 Signature ok Signature ok
-subject=C = RO, ST = Romania, L = Bucharest, O = AX, OU = AX Software, CN = item-ax32034, emailAddress = item@ax.com+subject=C = RO, ST = Romania, L = Bucharest, O = AX, OU = AX Software, CN = item-ax, emailAddress = item@ax.com
 Getting CA Private Key Getting CA Private Key
 Enter pass phrase for ca.key: Enter pass phrase for ca.key:
ssl/generate-certificates-self-signed.txt ยท Last modified: 2020/08/08 20:58 by odefta