柚子快報(bào)激活碼778899分享:ssl ip 自簽證書
柚子快報(bào)激活碼778899分享:ssl ip 自簽證書
一、創(chuàng)建私鑰
[root@shuaishuai ~]# openssl genrsa -out ca.key 2048
示例:
注:此時(shí)目錄下會(huì)生成一個(gè) ca.key 文件
二、創(chuàng)建公鑰
[root@shuaishuai ~]# openssl req -new -x509 -days 208 -key ca.key -out ca.crt
示例:
注:此時(shí)目錄下會(huì)生成一個(gè) ca.crt 文件
三、生成密鑰對(duì)
1.先準(zhǔn)備兩個(gè)文件,分別是openssl.cnf 和 v3.ext
[root@shuaishuai ~]# vim openssl.cnf
openssl.cnf 內(nèi)容如下:
[req]
distinguished_name = req_distinguished_name
req_extensions = v3_req
[req_distinguished_name]
countryName = Country Name (2 letter code)
countryName_default = US
stateOrProvinceName = State or Province Name (full name)
stateOrProvinceName_default = NY
localityName = Locality Name (eg, city)
localityName_default = NYC
organizationalUnitName = Organizational Unit Name (eg, section)
organizationalUnitName_default = xxx
commonName = xxx
commonName_max = 64
[ v3_req ]
# Extensions to add to a certificate request
basicConstraints = CA:TRUE
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
subjectAltName = @alt_names
[alt_names]
IP.1 = 192.168.1.145
IP.2 = 192.168.1.140
[root@shuaishuai ~]# vim v3.ext
v3.ext 內(nèi)容如下:
authorityKeyIdentifier=keyid,issuer
basicConstraints=CA:FALSE
keyUsage=digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment
subjectAltName=@alt_names
[alt_names]
IP.1 = 192.168.0.145
IP.2 = 192.168.1.140
注意:以上兩個(gè)文件是相關(guān)聯(lián)的
四、 生成服務(wù)器證書
1.生成私鑰
[root@shuaishuai ~]# openssl genrsa -out server.key 2048
示例:
注:此時(shí)會(huì)生成一個(gè) server.key 文件
2.生成公鑰
[root@shuaishuai ~]# openssl req -new -days 208 -key server.key -out server.csr -config openssl.cnf
示例:
3.自簽名
[root@shuaishuai ~]# openssl x509 -days 208 -req -sha256 -extfile v3.ext -CA ca.crt -CAkey ca.key -CAcreateserial -in server.csr -out server.crt
示例:
注:目錄下會(huì)生成 server.key 和 server.crt 兩個(gè)文件。
keytool -importcert -trustcacerts -keystore "/usr/local/java/jre/lib/security/cacerts" -alias bd_admin -file "/usr/local/BambooCloudBDC/private/tls/myCert.cer" -storepass "changeit"
柚子快報(bào)激活碼778899分享:ssl ip 自簽證書
推薦閱讀
本文內(nèi)容根據(jù)網(wǎng)絡(luò)資料整理,出于傳遞更多信息之目的,不代表金鑰匙跨境贊同其觀點(diǎn)和立場(chǎng)。
轉(zhuǎn)載請(qǐng)注明,如有侵權(quán),聯(lián)系刪除。