1. 程式人生 > >自簽證書的創建與導入

自簽證書的創建與導入

echo sub username ice tool key keystore web rck

1.創建根秘鑰        openssl genrsa -out ca.key 2048
2.創建根證書 openssl req -new -x509 -days 36500 -sha256 -key ca.key -out openas.crt -subj "/C=CN/ST=Jiangsu/L=Nanjing/O=HuaweiCA/OU=112.13.167.7"
3.創建SSL證書私匙 openssl genrsa -out server.key 2048位
4.建立SSL證書 openssl req -new -sha256 -key server.key -out server.csr -subj
"/C=CN/ST=Jiangsu/L=Nanjing/O=HuaweiCA/OU=112.13.167.7/CN=112.13.167.7"
5. mkdir demoCA
cd demoCA
mkdir newcerts
touch index.txt
i:
echo ‘01‘ > serial
cd ..
6.用CA根證書簽署SSL自建證書 openssl ca -md sha256 -in server.csr -out server.crt -cert openas.crt -keyfile ca.key


7.openssl pkcs12 -export -out certificate.pfx -inkey privateKey.key -in certificate.crt

8.keytool -importkeystore -srckeystore subcert.p12 -destkeystore subcert.jks -srcstoretype pkcs12

新建keystore keytool -genkey -alias newkeystore -keyalg RSA -validity 20000 -keystore newkeystore

將證書導入keystore keytool -import -file openas.crt -keystore newkeystore

自簽證書的創建與導入