]
},
“client”: {
“expiry”: “8760h”,
“usages”: [
“signing”,
“key encipherment”,
“client auth”
]
},
“peer”: {
“expiry”: “8760h”,
“usages”: [
“signing”,
“key encipherment”,
“server auth”,
“client auth”
]
}
}
}
}
自定义ca-csr.json:
-
CN即common name,hosts可以指定多个(泛)域名以及多个IP地址
-
key:指定了加密算法,一般使用rsa(size:2048)
{
“CN”: “example.net”,
“hosts”: [
“example.net”,
“www.example.net”
],
“key”: {
“algo”: “ecdsa”,
“size”: 256
},
“names”: [
{
“C”: “US”,
“L”: “CA”,
“ST”: “San Francisco”
}
]
}
-
接下来,就可以根据ca-csr.json来自签CA了,通