/etc/pki/tls/misc/CA -newca
CA certificate filename (or enter to create) 直接回车
Making CA certificate ...
Generating a 2048 bit RSA private key
.............................+++
...................................+++
writing new private key to '/etc/pki/CA/private/./cakey.pem'
Enter PEM pass phrase: 输入密码,保护私钥。
Verifying - Enter PEM pass phrase: 确认密码
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [XX]:CN
State or Province Name (full name) []:shanxi
Locality Name (eg, city) [Default City]:yuanqu
Organization Name (eg, company) [Default Company Ltd]:gf-beyond
Organizational Unit Name (eg, section) []:linux
Common Name (eg, your name or your server's hostname) []:gf-beyond.com 普通名称(例如,您的姓名或您的服务器的主机名),随便写. 指定 CA 认证中心服务器的名字
Email Address []:gaofei0428@yeah.net
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []: 直接回车
An optional company name []: 直接回车
Using configuration from /etc/pki/tls/openssl.cnf CA 服务器的配置文件。上面修改的内容会添加到这个配置文件中
Enter pass phrase for /etc/pki/CA/private/./cakey.pem: 输入刚才保护 CA私钥的密码
Check that the request matches the signature
Signature ok
Certificate Details:
Serial Number:
bc:78:e6:1d:88:8f:b1:4a
Validity
Not Before: Aug 1 00:36:31 2021 GMT
Not After : Jul 31 00:36:31 2024 GMT
Subject:
countryName = CN
stateOrProvinceName = shanxi
organizationName = gf-beyond
organizationalUnitName = linux
commonName = gf-beyond.com
emailAddress = gaofei0428@yeah.net
X509v3 extensions:
X509v3 Subject Key Identifier:
F6:EE:7D:32:F4:77:C9:8B:AC:FD:97:9C:35:50:74:C4:FE:7C:3B:F4
X509v3 Authority Key Identifier:
keyid:F6:EE:7D:32:F4:77:C9:8B:AC:FD:97:9C:35:50:74:C4:FE:7C:3B:F4
X509v3 Basic Constraints:
CA:TRUE
Certificate is to be certified until Jul 31 00:36:31 2024 GMT (1095 days)
Write out database with 1 new entries
Data Base Updated
到此 CA 认证中心就搭建好了。
查看生成的 CA 根证书,根证书中包括 CA 公钥
cat /etc/pki/CA/cacert.pem
Enter pass phrase for /etc/httpd/conf.d/server.key:
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [XX]:CN
State or Province Name (full name) []:shanxi
Locality Name (eg, city) [Default City]:yuanqu
Organization Name (eg, company) [Default Company Ltd]:gf-beyond
Organizational Unit Name (eg, section) []:linux
Common Name (eg, your name or your server's hostname) []:gf-beyond.cn 这里要求输入的 CommonName 必须与通过浏览器访问您网站的 URL 完全相同,否则用户会发现您服务器证书的通用名与站点的名字不匹配,用户就会怀疑您的证书的真实性。可以使域名也可以使用IP地址。
Email Address []:gaofei0428@yeah.net
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
在 192.168.2.40 上 CA 签名
openssl ca -keyfile /etc/pki/CA/private/cakey.pem -cert /etc/pki/CA/cacert.pem -in /tmp/server.csr -out /opt/ca/server.crt
Using configuration from /etc/pki/tls/openssl.cnf
Enter pass phrase for /etc/pki/CA/private/cakey.pem:
Check that the request matches the signature
Signature ok
Certificate Details:
Serial Number:
bc:78:e6:1d:88:8f:b1:4b
Validity
Not Before: Aug 1 01:11:44 2021 GMT
Not After : Aug 1 01:11:44 2022 GMT
Subject:
countryName = CN
stateOrProvinceName = shanxi
organizationName = gf-beyond
organizationalUnitName = linux
commonName = gf-beyond.cn
emailAddress = gaofei0428@yeah.net
X509v3 extensions:
X509v3 Basic Constraints:
CA:TRUE
Netscape Comment:
OpenSSL Generated Certificate
X509v3 Subject Key Identifier:
68:9E:67:34:24:88:2B:68:F0:EC:19:73:4C:AC:0A:35:93:60:80:F9
X509v3 Authority Key Identifier:
keyid:F6:EE:7D:32:F4:77:C9:8B:AC:FD:97:9C:35:50:74:C4:FE:7C:3B:F4
Certificate is to be certified until Aug 1 01:11:44 2022 GMT (365 days)
Sign the certificate? [y/n]:y
1 out of 1 certificate requests certified, commit? [y/n]y
Write out database with 1 new entries
Data Base Updated
cat server.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
bc:78:e6:1d:88:8f:b1:4b
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=CN, ST=shanxi, O=gf-beyond, OU=linux, CN=gf-beyond.com/emailAddress=gaofei0428@yeah.net
Validity
Not Before: Aug 1 01:11:44 2021 GMT
Not After : Aug 1 01:11:44 2022 GMT
Subject: C=CN, ST=shanxi, O=gf-beyond, OU=linux, CN=gf-beyond.cn/emailAddress=gaofei0428@yeah.net
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b9:7d:5f:64:f0:cf:d5:e1:a1:b9:63:0b:c7:1b:
20:ff:52:ca:70:5a:5a:68:82:11:c1:d2:f1:2a:ed:
59:ca:88:72:ac:48:1f:af:ee:ed:43:ff:5b:02:da:
97:84:50:d7:35:3f:1d:4e:bc:d6:f9:1b:0a:f0:7b:
cd:eb:e3:3e:c2:0a:a6:18:a0:33:2a:86:52:5c:21:
8c:7a:6d:18:a1:f6:20:ac:1d:3b:7b:b0:29:2a:98:
1f:51:90:f8:dd:e2:36:5b:70:27:13:ed:a2:51:80:
ae:8b:94:5a:16:1f:db:f7:d8:93:f9:ad:18:50:30:
2c:16:81:e1:f1:33:7d:d4:a7:a3:e9:63:d4:d4:09:
c7:fb:cd:a6:cf:e9:41:73:2e:c5:c2:aa:04:82:c4:
12:1f:ad:7d:c0:86:4e:af:b7:ef:e5:d3:2f:7c:f8:
dc:bd:ad:e5:7a:3b:b8:45:11:bc:0f:18:1a:4c:a9:
c0:82:62:03:9f:9c:ae:9e:5e:b6:b7:57:ec:3d:03:
66:19:71:53:93:7a:2e:c8:f7:db:88:6f:04:bd:30:
74:de:fe:17:79:33:22:a6:29:18:7a:07:68:f7:3d:
e7:87:31:06:29:ee:d2:6e:f9:bd:7a:e3:9e:5c:93:
ad:9f:fd:2c:e2:c3:93:8f:b3:fe:cb:bb:ca:49:56:
79:db
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints:
CA:TRUE
Netscape Comment:
OpenSSL Generated Certificate
X509v3 Subject Key Identifier:
68:9E:67:34:24:88:2B:68:F0:EC:19:73:4C:AC:0A:35:93:60:80:F9
X509v3 Authority Key Identifier:
keyid:F6:EE:7D:32:F4:77:C9:8B:AC:FD:97:9C:35:50:74:C4:FE:7C:3B:F4
Signature Algorithm: sha256WithRSAEncryption
9b:25:55:2f:33:c3:9c:a9:1d:53:d4:c3:38:04:ee:7c:8a:e1:
29:4c:b3:e3:f3:f8:73:a1:f6:60:58:3b:c5:d7:be:68:7c:80:
e8:64:97:e4:2c:e0:21:88:18:ce:8f:4e:c9:d2:0f:8c:fc:f5:
4a:48:b2:0e:51:c9:51:a5:73:92:09:21:8a:40:18:64:39:36:
3e:65:3f:92:78:7a:da:d1:4b:14:09:ab:5d:c8:31:91:a9:34:
b7:2b:1a:84:78:36:2b:5a:89:da:c3:12:a2:d2:e8:4c:88:a6:
03:f5:d0:81:bd:b4:76:4a:6b:f1:07:0a:68:9c:cb:6a:ec:c9:
9f:37:d1:7f:1e:27:67:11:e0:89:18:3b:c4:9d:df:ad:df:21:
21:52:01:48:2a:37:d3:a9:ec:c0:b0:e7:5e:22:8a:2c:17:06:
ea:5e:40:c8:36:e9:87:09:1e:f9:dc:2f:fd:82:2f:95:40:59:
6b:44:9d:23:ae:04:d3:7b:a8:71:92:a1:1c:8c:eb:ff:4f:78:
68:3f:33:f6:38:f6:c3:06:45:72:20:2a:41:4f:8e:97:51:bc:
f6:0a:33:c2:72:a0:0c:66:a9:c1:57:80:d5:25:2f:fb:fb:33:
fc:d0:b8:cd:56:54:c2:ba:98:aa:42:17:1d:44:dc:23:a9:6c:
55:37:cd:59
-----BEGIN CERTIFICATE-----
MIID/DCCAuSgAwIBAgIJALx45h2Ij7FLMA0GCSqGSIb3DQEBCwUAMH4xCzAJBgNV
BAYTAkNOMQ8wDQYDVQQIDAZzaGFueGkxEjAQBgNVBAoMCWdmLWJleW9uZDEOMAwG
A1UECwwFbGludXgxFjAUBgNVBAMMDWdmLWJleW9uZC5jb20xIjAgBgkqhkiG9w0B
CQEWE2dhb2ZlaTA0MjhAeWVhaC5uZXQwHhcNMjEwODAxMDExMTQ0WhcNMjIwODAx
MDExMTQ0WjB9MQswCQYDVQQGEwJDTjEPMA0GA1UECAwGc2hhbnhpMRIwEAYDVQQK
DAlnZi1iZXlvbmQxDjAMBgNVBAsMBWxpbnV4MRUwEwYDVQQDDAxnZi1iZXlvbmQu
Y24xIjAgBgkqhkiG9w0BCQEWE2dhb2ZlaTA0MjhAeWVhaC5uZXQwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC5fV9k8M/V4aG5YwvHGyD/UspwWlpoghHB
0vEq7VnKiHKsSB+v7u1D/1sC2peEUNc1Px1OvNb5Gwrwe83r4z7CCqYYoDMqhlJc
IYx6bRih9iCsHTt7sCkqmB9RkPjd4jZbcCcT7aJRgK6LlFoWH9v32JP5rRhQMCwW
geHxM33Up6PpY9TUCcf7zabP6UFzLsXCqgSCxBIfrX3Ahk6vt+/l0y98+Ny9reV6
O7hFEbwPGBpMqcCCYgOfnK6eXra3V+w9A2YZcVOTei7I99uIbwS9MHTe/hd5MyKm
KRh6B2j3PeeHMQYp7tJu+b16455ck62f/Sziw5OPs/7Lu8pJVnnbAgMBAAGjfjB8
MAwGA1UdEwQFMAMBAf8wLAYJYIZIAYb4QgENBB8WHU9wZW5TU0wgR2VuZXJhdGVk
IENlcnRpZmljYXRlMB0GA1UdDgQWBBRonmc0JIgraPDsGXNMrAo1k2CA+TAfBgNV
HSMEGDAWgBT27n0y9HfJi6z9l5w1UHTE/nw79DANBgkqhkiG9w0BAQsFAAOCAQEA
myVVLzPDnKkdU9TDOATufIrhKUyz4/P4c6H2YFg7xde+aHyA6GSX5CzgIYgYzo9O
ydIPjPz1SkiyDlHJUaVzkgkhikAYZDk2PmU/knh62tFLFAmrXcgxkak0tysahHg2
K1qJ2sMSotLoTIimA/XQgb20dkpr8QcKaJzLauzJnzfRfx4nZxHgiRg7xJ3frd8h
IVIBSCo306nswLDnXiKKLBcG6l5AyDbphwke+dwv/YIvlUBZa0SdI64E03uocZKh
HIzr/094aD8z9jj2wwZFciAqQU+Ol1G89gozwnKgDGapwVeA1SUv+/sz/NC4zVZU
wrqYqkIXHUTcI6lsVTfNWQ==
-----END CERTIFICATE-----
将证书复制到 192.168.2.41
scp server.crt root@192.168.2.41:/opt/ca
网站声明:如果转载,请联系本站管理员。否则一切后果自行承担。
添加我为好友,拉您入交流群!
请使用微信扫一扫!