OpenSSL Creating a Private Certificate Authority: Difference between revisions
Jump to navigation
Jump to search
Line 18: | Line 18: | ||
#:<tt>'''# openssl ca -config openssl.cnf -policy policy_anything -out certs/<certificate>.crt -infiles csrs/<certificate signing request>.csr'''</tt> | #:<tt>'''# openssl ca -config openssl.cnf -policy policy_anything -out certs/<certificate>.crt -infiles csrs/<certificate signing request>.csr'''</tt> | ||
#Enable SubjectAltName | #Enable SubjectAltName | ||
##Locate the '''[ proxy_cert_ext ]''' stanza. | ##Locate the <tt>'''[ proxy_cert_ext ]'''</tt> stanza. | ||
##Uncomment '''subjectAltName=email:copy''' and '''subjectAltName=email:move''' lines. | ##Uncomment <tt>'''subjectAltName=email:copy'''</tt> and <tt>'''subjectAltName=email:move'''</tt> lines. | ||
== Debian/Ubuntu == | == Debian/Ubuntu == |
Revision as of 02:55, 15 November 2020
Red Hat Enterprise Linux/CentOS
- Move to the Certificate Authority directory.
- # cd /etc/pki/CA
- # mkdir /etc/pki/CA/{csrs,private,crl,newcerts,certs}
- Create the index.txt and serial files needed for the Certificate Authority.
- # touch /etc/pki/CA/index.txt
- # touch /etc/pki/CA/serial
- # echo 01 > serial
- Copy the existing openssl.cnf to the Certificate Authority directory.
- # cp /etc/pki/tls/openssl.cnf /etc/pki/CA/.
- Generate the CA Private Key and CA Certificate:
- # cd /etc/pki/CA/
- # openssl req -config openssl.cnf -new -x509 -extensions v3_ca -keyout private/cakey.pem -out cacert.pem -days 36525
- To sign a CSR.
- Upload the <certificate signing request>.csr to /etc/pki/CA/csrs/.
- # cd /etc/pki/CA
- # openssl ca -config openssl.cnf -policy policy_anything -out certs/<certificate>.crt -infiles csrs/<certificate signing request>.csr
- Enable SubjectAltName
- Locate the [ proxy_cert_ext ] stanza.
- Uncomment subjectAltName=email:copy and subjectAltName=email:move lines.