生成私钥和证书申请文件:
openssl req -utf8 -new -newkey rsa:2048 -sha256 -nodes -out djqtest.csr -keyout djqtest.key -subj "/C=CN/ST=Shanghai/L=Shanghai/O=公司名称/OU=项目名称/CN=域名"
申请x509证书:
openssl x509 -req -days 3650 -in djq.csr -CA openssl.crt -CAkey openssl.key -CAcreateserial -out openssl.crt
CA相关命令
CA
cd /etc/pki/CA
生产CA密钥
openssl genrsa -out private/cakey.pem 2048
使用req命令生成自签证书:
openssl req -new -x509 -key private/cakey.pem -out cacert.pem
touch ./{serial,index.txt}
echo 01 > serial
签证书:
cd /root
openssl ca -in test.csr -out test.crt
可以在线查看证书文件
https://holtstrom.com/michael/tools/asn1decoder.php