Jump to content

SSL Certificate signed by your own CA: Difference between revisions

From Costa's Wiki
Created page with "1. Generate self-signed root CA certificate mkdir -p /root/internalca cd /root/internalca openssl genrsa -out rootCAKey.pem 2048 openssl req -x509 -sha256 -new -node..."
 
No edit summary
 
(One intermediate revision by the same user not shown)
Line 5: Line 5:
   openssl genrsa -out rootCAKey.pem 2048
   openssl genrsa -out rootCAKey.pem 2048
   openssl req -x509 -sha256 -new -nodes -key rootCAKey.pem -days 3650 -out rootCACert.pem
   openssl req -x509 -sha256 -new -nodes -key rootCAKey.pem -days 3650 -out rootCACert.pem
  to check it
  ''to check it''
   openssl x509 -in rootCACert.pem -text
   openssl x509 -in rootCACert.pem -text
   
   
Line 14: Line 14:
   openssl genrsa -out rbaServerKey.pem 2048
   openssl genrsa -out rbaServerKey.pem 2048
   openssl req -new -key rbaServerKey.pem -sha256 -out rbaServerCert.csr
   openssl req -new -key rbaServerKey.pem -sha256 -out rbaServerCert.csr
  to check CSR
  ''to check CSR''
   openssl req -in rbaServerCert.csr -noout -text
   openssl req -in rbaServerCert.csr -noout -text
You can use config file
vi ServerCertReq.config
[req]
req_extensions = v3_req
distinguished_name = dn
prompt = no
[dn]
CN = <FQDN of your RBA server>
C = <Country Name (2 letter code)>
L = <Locality Name (eg, city)>
O = <Organization Name (eg, company)>
OU = <Organizational Unit Name (eg, section)>
[v3_req]
subjectAltName = DNS:<FQDN of your RBA server>
''and to create CSR''
openssl req -new -key rbaServerKey.pem -sha256 -out rbaServerCert.csr -config ServerCertReq.config


3. Generate and sign certificate  
3. Generate and sign certificate  
   openssl x509 -req -sha256 -in rbaServerCert.csr -CA /root/internalca/rootCACert.pem -CAkey /root/internalca/rootCAKey.pem -CAcreateserial -out rbaServerCert.pem -days 365
   openssl x509 -req -sha256 -in rbaServerCert.csr -CA /root/internalca/rootCACert.pem -CAkey /root/internalca/rootCAKey.pem -CAcreateserial -out rbaServerCert.pem -days 365
  to check certificate  
  ''to check certificate''
   openssl x509 -in rbaServerCert.pem -text -noout
   openssl x509 -in rbaServerCert.pem -text -noout

Latest revision as of 19:32, 10 October 2023

1. Generate self-signed root CA certificate

 mkdir -p /root/internalca
 cd /root/internalca

 openssl genrsa -out rootCAKey.pem 2048
 openssl req -x509 -sha256 -new -nodes -key rootCAKey.pem -days 3650 -out rootCACert.pem
to check it
 openssl x509 -in rootCACert.pem -text

2. Generate certificate request

 mkdir -p /tmp/rbakeys
 cd /tmp/rbakeys

 openssl genrsa -out rbaServerKey.pem 2048
 openssl req -new -key rbaServerKey.pem -sha256 -out rbaServerCert.csr
to check CSR
 openssl req -in rbaServerCert.csr -noout -text

You can use config file

vi ServerCertReq.config

[req]
req_extensions = v3_req
distinguished_name = dn
prompt = no

[dn]
CN = <FQDN of your RBA server>
C = <Country Name (2 letter code)>
L = <Locality Name (eg, city)>
O = <Organization Name (eg, company)>
OU = <Organizational Unit Name (eg, section)>

[v3_req]
subjectAltName = DNS:<FQDN of your RBA server> 

and to create CSR
openssl req -new -key rbaServerKey.pem -sha256 -out rbaServerCert.csr -config ServerCertReq.config

3. Generate and sign certificate

 openssl x509 -req -sha256 -in rbaServerCert.csr -CA /root/internalca/rootCACert.pem -CAkey /root/internalca/rootCAKey.pem -CAcreateserial -out rbaServerCert.pem -days 365
to check certificate 
 openssl x509 -in rbaServerCert.pem -text -noout