亚洲综合社区欧美综合色-欧美逼逼一区二区三区-国产老熟女高潮精品网站-国产日韩最新视频在线看

始創(chuàng)于2000年 股票代碼:831685
咨詢熱線:0371-60135900 注冊有禮 登錄
  • 掛牌上市企業(yè)
  • 60秒人工響應
  • 99.99%連通率
  • 7*24h人工
  • 故障100倍補償
全部產(chǎn)品
您的位置: 網(wǎng)站首頁 > 幫助中心>文章內容

Openssl幾個簡單的功能命令使用

發(fā)布時間:  2012/8/10 15:18:42
 Openssl的功能十分強大,在這里我只是給大家講一些openssl的幾個簡單的命令使用:生成密鑰,生成證書請求,生成證書,及作為CA來說,來生成一個自簽證書。

  1:生成ca的自簽證書:

  #cd /etc/pki/CA 進入該目錄,CA證書必須建立在該目錄中

  #openssl genrsa 2048 > /privat/my.key

  生成一個密鑰

  #vim /etc/pki/tls/openssl.cnf

  將[ CA_default ]中的dir 選項改為:/etc/pki/CA

  #mkdir ./newcerts

  證書生成后會自動生成一些序列號文件和信息文件,而這些文件要放在newcerts目錄中,所以要是先創(chuàng)建它,否則生成證書時會報錯提示說沒有改文件,以致無法完成

  #touch ./{serial ,index.txt}

  建立序列號文件和index文檔

  #echo “00” > ./serial

  給定一個序列號初始值

  #openssl –x509 –new –key private/cakey.pem –out ./cacert.pem –days 1000

  生成ca證書

  2:證書的簽署

  #mkdir /root/testcrt

  #cd /root/testcrt

  #openssl genrsa 1024 > my.key

  生成密鑰

  Generating RSA private key, 1024 bit long modulus

  ..........................++++++

  ...++++++

  e is 65537 (0x10001)

  ----------------------------------

  #openssl rsa –in my.key –pubout –out test.pub

  查看剛剛生成的密鑰文件

  #openssl req –new –key my.key –out my.csr

  生成證書請求

  --------------------------------------

  You are about to be asked to enter information that will be incorporated

  into your certificate request.

  What you are about to enter is what is called a Distinguished Name or a DN.

  There are quite a few fields but you can leave some blank

  For some fields there will be a default value,

  If you enter '.', the field will be left blank.

  -----

  Country Name (2 letter code) [GB]:NA

  State or Province Name (full name) [Berkshire]:HA

  Locality Name (eg, city) [Newbury]:ZZ

  Organization Name (eg, company) [My Company Ltd]:CA

  Organizational Unit Name (eg, section) []:station173.example.com

  Common Name (eg, your name or your server's hostname) []:a.example.com

  Email Address []:root@a.example.com

  Please enter the following 'extra' attributes

  to be sent with your certificate request

  A challenge password []:

  An optional company name []:

  ---------------------------------------------------

  #openssl ca –in my.csr –out my.crt –days 1000

  由ca給其生成證書

  ----------------------------------------------------

  Using configuration from /etc/pki/tls/openssl.cnf

  Check that the request matches the signature

  Signature ok

  Certificate Details:

  Serial Number: 2 (0x2)

  Validity

  Not Before: Feb 25 15:28:21 2010 GMT

  Not After : Nov 21 15:28:21 2012 GMT

  Subject:

  countryName = CN

  stateOrProvinceName = HA

  organizationName = CA

  organizationalUnitName = station173.example.com

  commonName = a.example.com

  emailAddress = root@a.example.com

  X509v3 extensions:

  X509v3 Basic Constraints:

  CA:FALSE

  Netscape Comment:

  OpenSSL Generated Certificate

  X509v3 Subject Key Identifier:

  A6:66:7E:D6:4E:70:0F:60:3B:CE:D8:7F:56:B2:D7:7C:64:8A:4B:25

  X509v3 Authority Key Identifier:

  keyid:CB:79:BF:95:34:53:96:EE:79:8B:48:C2:6E:77:B4:E6:AB:23:C0:F3

  Certificate is to be certified until Nov 21 15:28:21 2012 GMT (1000 days)

  Sign the certificate? [y/n]:y

  1 out of 1 certificate requests certified, commit? [y/n]y

  Write out database with 1 new entries

  Data Base Updated

  ------------------------------------------------------------

  #openssl x509 –in my.crt –noout –text


本文出自:億恩科技【1tcdy.com】

服務器租用/服務器托管中國五強!虛擬主機域名注冊頂級提供商!15年品質保障!--億恩科技[ENKJ.COM]

  • 您可能在找
  • 億恩北京公司:
  • 經(jīng)營性ICP/ISP證:京B2-20150015
  • 億恩鄭州公司:
  • 經(jīng)營性ICP/ISP/IDC證:豫B1.B2-20060070
  • 億恩南昌公司:
  • 經(jīng)營性ICP/ISP證:贛B2-20080012
  • 服務器/云主機 24小時售后服務電話:0371-60135900
  • 虛擬主機/智能建站 24小時售后服務電話:0371-60135900
  • 專注服務器托管17年
    掃掃關注-微信公眾號
    0371-60135900
    Copyright© 1999-2019 ENKJ All Rights Reserved 億恩科技 版權所有  地址:鄭州市高新區(qū)翠竹街1號總部企業(yè)基地億恩大廈  法律顧問:河南亞太人律師事務所郝建鋒、杜慧月律師   京公網(wǎng)安備41019702002023號
      1
     
     
     
     

    0371-60135900
    7*24小時客服服務熱線