SSL Certificate with SAN: Difference between revisions
Created page with "==How to create a self-signed SSL Certificate with SubjectAltName(SAN)== Generate a Private Key openssl genrsa -des3 -out example.com.key 2048 Generate a CSR (Certificate Sig..." |
|||
| Line 25: | Line 25: | ||
[ req ] | [ req ] | ||
prompt = no | |||
days = 3650 | |||
default_bits = 2048 | default_bits = 2048 | ||
distinguished_name = req_distinguished_name | distinguished_name = req_distinguished_name | ||
req_extensions = req_ext | req_extensions = req_ext | ||
[ req_distinguished_name ] | [ req_distinguished_name ] | ||
countryName | countryName = Country Name (2 letter code) | ||
stateOrProvinceName | stateOrProvinceName = State or Province Name (full name) | ||
localityName = Locality Name (eg, city) | localityName = Locality Name (eg, city) | ||
organizationName = Organization Name (eg, company) | organizationName = Organization Name (eg, company) | ||
commonName = Common Name (e.g. server FQDN or YOUR name) | commonName = Common Name (e.g. server FQDN or YOUR name) | ||
emailAddress = [email protected] | |||
[ req_ext ] | [ req_ext ] | ||
subjectAltName = @alt_names | subjectAltName = @alt_names | ||
[alt_names] | [alt_names] | ||
DNS.1 = test.domain.com | DNS.1 = test.domain.com | ||
Revision as of 19:16, 4 October 2023
How to create a self-signed SSL Certificate with SubjectAltName(SAN)
Generate a Private Key
openssl genrsa -des3 -out example.com.key 2048
Generate a CSR (Certificate Signing Request)
openssl req -new -key example.com.key -out example.com.csr
Remove Passphrase from Key
cp example.com.key example.com.key.org openssl rsa -in example.com.key.org -out example.com.key
Create config file for SAN
touch v3.ext
File content
subjectKeyIdentifier = hash authorityKeyIdentifier = keyid:always,issuer:always basicConstraints = CA:TRUE keyUsage = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment, keyAgreement, keyCertSign subjectAltName = DNS:example.com, DNS:*.example.com issuerAltName = issuer:copy
Create the certificate
openssl x509 -req -in example.com.csr -signkey example.com.key -out example.com.crt -days 3650 -sha256 -extfile v3.ext
How to create CSR for a SAN certificate
Create a file named mysan.cnf with the following information at the location:
[ req ] prompt = no days = 3650 default_bits = 2048 distinguished_name = req_distinguished_name req_extensions = req_ext
[ req_distinguished_name ] countryName = Country Name (2 letter code) stateOrProvinceName = State or Province Name (full name) localityName = Locality Name (eg, city) organizationName = Organization Name (eg, company) commonName = Common Name (e.g. server FQDN or YOUR name) emailAddress = [email protected]
[ req_ext ] subjectAltName = @alt_names
[alt_names] DNS.1 = test.domain.com DNS.2 = test2.domain.com DNS.3 = test3.domain.com
Verify the server FQDN mentioned under alt_names, where alt_names section is the one you have to change for additional DNS.
Generate the CSR and KEY file with this command.
openssl req -out server.csr -newkey rsa:2048 -nodes -keyout server.key -config mysan.cnf
Enter the details to complete the CSR. Common Name must be the FQDN of the inSync master server. Convert the server.key to RSA format using:
openssl rsa -in server.key -out myserver.key
You now have the myserver.key file in the required RSA format. Thus, the CSR and private key are created. Verification To verify the CSR for SAN:
openssl req -noout -text -in server.csr
Under Subject Alternative Name, the different DNS names must appear for which this CSR is valid.
DNS:test.domain.com, DNS:test2.domain.com, DNS:test3.domain.com