记录一个openssl在windows下面测试

工具:http://code.google.com/p/openssl-for-windows/

 

genrsa -out ca/ca2-key.pem 1024

req -new -out ca/ca-req.csr -key ca/ca2-key.pem 

x509 -req -in ca/ca-req.csr -out ca/ca2-cert.pem -signkey ca/ca2-key.pem -days 3650


pkcs12 -export -clcerts -in ca/ca2-cert.pem -inkey ca/ca2-key.pem -out ca/ca2.p12


genrsa -out server/server2-key.pem 1024 


req -new -out server/server2-req.csr -key server/server2-key.pem

 

x509 -req -in server/server2-req.csr -out server/server2-cert.pem -signkey server/server2-key.pem -CA ca/ca2-cert.pem -CAkey ca/ca2-key.pem -CAcreateserial -days 3650 

 

pkcs12 -export -clcerts -in server/server2-cert.pem -inkey server/server2-key.pem -out server/server2.p12 


genrsa -out client/client2-key.pem 1024


req -new -out client/client2-req.csr -key client/client2-key.pem

 

x509 -req -in client/client2-req.csr -out client/client2-cert.pem -signkey client/client2-key.pem -CA ca/ca2-cert.pem -CAkey ca/ca2-key.pem -CAcreateserial -days 3650 

 

pkcs12 -export -clcerts -in client/client2-cert.pem -inkey client/client2-key.pem -out client/client2.p12

 


keytool -keystore C:\openssl\bin\jks\truststore2.jks -keypass changeit -storepass changeit -alias ca -import -trustcacerts -file C:\openssl\bin\ca\ca2-cert.pem 


<!-- tomcat 6.0.20 -->
<Connector port="8443" protocol="HTTP/1.1" SSLEnabled="true"
               maxThreads="150" scheme="https" secure="true"
               clientAuth="true" sslProtocol="TLS"
               keystoreFile="C:/openssl/bin/server/server2.p12" keystorePass="changeit" keystoreType="PKCS12" 
               truststoreFile="C:/openssl/bin/jks/truststore2.jks" truststorePass="changeit" truststoreType="JKS"/>

 

 

 

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值