Jump to content

SSL Certificate with SAN: Difference between revisions

From Costa's Wiki
Created page with "==How to create a self-signed SSL Certificate with SubjectAltName(SAN)== Generate a Private Key openssl genrsa -des3 -out example.com.key 2048 Generate a CSR (Certificate Sig..."
 
No edit summary
 
(3 intermediate revisions by the same user not shown)
Line 25: Line 25:


  [ req ]
  [ req ]
prompt            = no
days              = 3650
  default_bits      = 2048
  default_bits      = 2048
  distinguished_name = req_distinguished_name
  distinguished_name = req_distinguished_name
  req_extensions    = req_ext
  req_extensions    = req_ext
  [ req_distinguished_name ]
  [ req_distinguished_name ]
  countryName                 = Country Name (2 letter code)
  countryName               = Country Name (2 letter code)
  stateOrProvinceName         = State or Province Name (full name)
  stateOrProvinceName       = State or Province Name (full name)
  localityName              = Locality Name (eg, city)
  localityName              = Locality Name (eg, city)
  organizationName          = Organization Name (eg, company)
  organizationName          = Organization Name (eg, company)
  commonName                = Common Name (e.g. server FQDN or YOUR name)
  commonName                = Common Name (e.g. server FQDN or YOUR name)
emailAddress              = [email protected]
  [ req_ext ]
  [ req_ext ]
  subjectAltName = @alt_names
  subjectAltName = @alt_names
  [alt_names]
  [alt_names]
  DNS.1  = test.domain.com
  DNS.1  = test.domain.com
Line 56: Line 62:


DNS:test.domain.com, DNS:test2.domain.com, DNS:test3.domain.com
DNS:test.domain.com, DNS:test2.domain.com, DNS:test3.domain.com
NOTE:
openssl req -x509 -nodes -days 3650 -newkey rsa:2048 -keyout $1.key -out $1.pem -config mysan.cnf -extensions 'req_ext'
== Update ==
If you are using OpenSSL 1.1.1 or higher you can simply use the -addext "subjectAltName = parameter like so:
openssl req -nodes -x509 -sha256 -newkey rsa:4096 \
  -keyout example.org.key \
  -out example.org.crt \
  -days 356 \
  -subj "/C=NL/ST=Zuid Holland/L=Rotterdam/O=ACME Corp/OU=IT Dept/CN=example.org"  \
  -addext "subjectAltName = DNS:localhost,DNS:example.org"
If you use an older version of OpenSSL, you can use bash process substitution to provide an OpenSSL config file directly without saving that file anywhere:
openssl req -nodes -x509 -sha256 -newkey rsa:4096 \
  -keyout example.org.key \
  -out example.org.crt \
  -days 356 \
  -subj "/C=NL/ST=Zuid Holland/L=Rotterdam/O=ACME Corp/OU=IT Dept/CN=example.org" \
  -extensions san \
  -config <( \
  echo '[req]'; \
  echo 'distinguished_name=req'; \
  echo '[san]'; \
  echo 'subjectAltName=DNS:localhost,DNS:example.org')

Latest revision as of 19:54, 4 October 2023

How to create a self-signed SSL Certificate with SubjectAltName(SAN)

[edit]

Generate a Private Key

openssl genrsa -des3 -out example.com.key 2048

Generate a CSR (Certificate Signing Request)

openssl req -new -key example.com.key -out example.com.csr

Remove Passphrase from Key

cp example.com.key example.com.key.org
openssl rsa -in example.com.key.org -out example.com.key

Create config file for SAN

touch v3.ext

File content

subjectKeyIdentifier   = hash
authorityKeyIdentifier = keyid:always,issuer:always
basicConstraints       = CA:TRUE
keyUsage               = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment, keyAgreement, keyCertSign
subjectAltName         = DNS:example.com, DNS:*.example.com
issuerAltName          = issuer:copy

Create the certificate

openssl x509 -req -in example.com.csr -signkey example.com.key -out example.com.crt -days 3650 -sha256 -extfile v3.ext

How to create CSR for a SAN certificate

[edit]

Create a file named mysan.cnf with the following information at the location:

[ req ]
prompt             = no
days               = 3650
default_bits       = 2048
distinguished_name = req_distinguished_name
req_extensions     = req_ext

[ req_distinguished_name ]
countryName                = Country Name (2 letter code)
stateOrProvinceName        = State or Province Name (full name)
localityName               = Locality Name (eg, city)
organizationName           = Organization Name (eg, company)
commonName                 = Common Name (e.g. server FQDN or YOUR name)
emailAddress               = [email protected]

[ req_ext ]
subjectAltName = @alt_names

[alt_names]
DNS.1   = test.domain.com
DNS.2   = test2.domain.com
DNS.3   = test3.domain.com


Verify the server FQDN mentioned under alt_names, where alt_names section is the one you have to change for additional DNS. Generate the CSR and KEY file with this command.

openssl req -out server.csr -newkey rsa:2048 -nodes -keyout server.key -config mysan.cnf

Enter the details to complete the CSR. Common Name must be the FQDN of the inSync master server. Convert the server.key to RSA format using:

openssl rsa -in server.key -out myserver.key

You now have the myserver.key file in the required RSA format. Thus, the CSR and private key are created. Verification To verify the CSR for SAN:

openssl req -noout -text -in server.csr

Under Subject Alternative Name, the different DNS names must appear for which this CSR is valid.

DNS:test.domain.com, DNS:test2.domain.com, DNS:test3.domain.com


NOTE:
openssl req -x509 -nodes -days 3650 -newkey rsa:2048 -keyout $1.key -out $1.pem -config mysan.cnf -extensions 'req_ext'

Update

[edit]
If you are using OpenSSL 1.1.1 or higher you can simply use the -addext "subjectAltName = parameter like so:

openssl req -nodes -x509 -sha256 -newkey rsa:4096 \
 -keyout example.org.key \
 -out example.org.crt \
 -days 356 \
 -subj "/C=NL/ST=Zuid Holland/L=Rotterdam/O=ACME Corp/OU=IT Dept/CN=example.org"  \
 -addext "subjectAltName = DNS:localhost,DNS:example.org" 

If you use an older version of OpenSSL, you can use bash process substitution to provide an OpenSSL config file directly without saving that file anywhere:

openssl req -nodes -x509 -sha256 -newkey rsa:4096 \
 -keyout example.org.key \
 -out example.org.crt \
 -days 356 \
 -subj "/C=NL/ST=Zuid Holland/L=Rotterdam/O=ACME Corp/OU=IT Dept/CN=example.org" \
 -extensions san \
 -config <( \
 echo '[req]'; \
 echo 'distinguished_name=req'; \
 echo '[san]'; \
 echo 'subjectAltName=DNS:localhost,DNS:example.org')