Ben's notes

Linux, Unix, network, radio...

User Tools

Site Tools


centos_7_tls_certificates

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Next revisionBoth sides next revision
centos_7_tls_certificates [2015/04/05 13:28] – [Server key and certificate] admincentos_7_tls_certificates [2015/04/05 13:30] – [Server key and certificate] admin
Line 13: Line 13:
 ====Server key and certificate==== ====Server key and certificate====
   * Generate server private key:<code>openssl genrsa -aes256 -out server.key 4096</code>   * Generate server private key:<code>openssl genrsa -aes256 -out server.key 4096</code>
-  * Create certificate signing request:<code>openssl req -new -sha256 -key server.key -out server.csr</code> +  * Create certificate signing request:<code>openssl req -new -sha256 -key server.key -out server.csr
-  * Sign server certificate, valid for 3 years:<code>openssl x509 -req -CA ca.crt -CAkey ca.key -days 1825 -extensions usr_cert -notext -md sha256 -set_serial 01 -in server.csr -out server.crt+
  
 Common name: <your server's FQDN></code> Common name: <your server's FQDN></code>
 +  * Sign server certificate, valid for 3 years:<code>openssl x509 -req -CA ca.crt -CAkey ca.key -days 1825 -extensions usr_cert -sha256 -set_serial 01 -in server.csr -out server.crt</code>
  
 =====Add CA certificate to trust store===== =====Add CA certificate to trust store=====
centos_7_tls_certificates.txt · Last modified: 2021/10/09 15:14 by 127.0.0.1