本文共 2456 字,大约阅读时间需要 8 分钟。
一、建立一CA颁发主机(机构)
1、生成私钥;2、自签证书[root@www1 ~]# (umask 077;openssl genrsa -out /etc/pki/CA/private/cakey.pem 4096)
Generating RSA private key, 4096 bit long modulus..............................++....++e is 65537 (0x10001)Country Name (2 letter code) [XX]:CN
二、向CA主机请求签署证书
1、生成私钥;2、生成证书签署请求,3、将请求(通过可靠方式)发送给CA主机;4、CA主机签署证书[root@localhost httpd]# mkdir ssl #以httpd为例,创建一目录,
[root@localhost httpd]# cd ssl/[root@localhost ssl]# (umask 077; openssl genrsa -out httpd.key 2048)Generating RSA private key, 2048 bit long modulus.+++...............+++e is 65537 (0x10001)Country Name (2 letter code) [XX]:CN
Please enter the following 'extra' attributes
to be sent with your certificate requestA challenge password []:[root@www1 ~]# openssl ca -in /tmp/httpd.csr -out /etc/pki/CA/certs/httpd.crt -days 365
[root@www1 ~]# cd /etc/pki/CA/[root@www1 CA]# cat index.txtV 190802095707Z 01 unknown /C=CN/ST=GuangXi/O=jinglin/OU=ca.jinglin.com/CN=www.jinglin.org/emailAddress=webmaster@jinglin.org[root@www1 CA]# scp certs/httpd.crt root@172.16.128.9:/etc/httpd/ssl/ #签完后发回,然后删除两台主机上的httpd.csr[root@localhost ssl]# openssl x509 -in httpd.crt -noout -serial -subject #查看证书信息
serial=01subject= /C=CN/ST=GuangXi/O=jinglin/OU=ca.jinglin.com/CN=www.jinglin.org/emailAddress=webmaster@jinglin.org私有CA构建完成
转载于:https://blog.51cto.com/10201808/2158019