证书和私钥是否匹配的校验
openssl x509 -noout -modulus -in server.crt
openssl rsa -noout -modulus -in server.key
# create private key openssl genrsa -aes128 -out server.key 2048 openssl rsa -text -in server.key # create public key openssl rsa -in server.key -pubout -out public.key #creating certificate signing request # input private.key openssl req -new -key server.key -out server.csr #check csr and confirm if correct openssl req -text -in server.csr -noout #creating CSR from existing certificate openssl x509 -x509toreq -in server.crt -out server.csr -signkey server.key #signing your own certificates openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt #creating a certificate without CSR, just input server.key openssl req -new -x509 -days 365 -key server.key -out server.crt # examing certificaes openssl x509 -text -in server.crt -noout |