Jump to content

SSL Certificate with SAN

From Costa's Wiki

How to create a self-signed SSL Certificate with SubjectAltName(SAN)

Generate a Private Key

openssl genrsa -des3 -out example.com.key 2048

Generate a CSR (Certificate Signing Request)

openssl req -new -key example.com.key -out example.com.csr

Remove Passphrase from Key

cp example.com.key example.com.key.org
openssl rsa -in example.com.key.org -out example.com.key

Create config file for SAN

touch v3.ext

File content

subjectKeyIdentifier   = hash
authorityKeyIdentifier = keyid:always,issuer:always
basicConstraints       = CA:TRUE
keyUsage               = digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment, keyAgreement, keyCertSign
subjectAltName         = DNS:example.com, DNS:*.example.com
issuerAltName          = issuer:copy

Create the certificate

openssl x509 -req -in example.com.csr -signkey example.com.key -out example.com.crt -days 3650 -sha256 -extfile v3.ext

How to create CSR for a SAN certificate

Create a file named mysan.cnf with the following information at the location:

[ req ]
prompt             = no
days               = 3650
default_bits       = 2048
distinguished_name = req_distinguished_name
req_extensions     = req_ext

[ req_distinguished_name ]
countryName                = Country Name (2 letter code)
stateOrProvinceName        = State or Province Name (full name)
localityName               = Locality Name (eg, city)
organizationName           = Organization Name (eg, company)
commonName                 = Common Name (e.g. server FQDN or YOUR name)
emailAddress               = [email protected]

[ req_ext ]
subjectAltName = @alt_names

[alt_names]
DNS.1   = test.domain.com
DNS.2   = test2.domain.com
DNS.3   = test3.domain.com


Verify the server FQDN mentioned under alt_names, where alt_names section is the one you have to change for additional DNS. Generate the CSR and KEY file with this command.

openssl req -out server.csr -newkey rsa:2048 -nodes -keyout server.key -config mysan.cnf

Enter the details to complete the CSR. Common Name must be the FQDN of the inSync master server. Convert the server.key to RSA format using:

openssl rsa -in server.key -out myserver.key

You now have the myserver.key file in the required RSA format. Thus, the CSR and private key are created. Verification To verify the CSR for SAN:

openssl req -noout -text -in server.csr

Under Subject Alternative Name, the different DNS names must appear for which this CSR is valid.

DNS:test.domain.com, DNS:test2.domain.com, DNS:test3.domain.com