x.503证书的制作和私钥.jks文件制作
分两套环境,Linux下制作和windows下制作.
1.linux环境下:
确保已安装了openssl,执行的命令如下:
openssl req -newkey rsa:2048 -x509 -days 5480 -keyout CA_SYRCB_Root.pem -out CA_SYRCB_Root.crt
openssl rsa -in CA_SYRCB_Root.pem -out CA_SYRCB_Root.pem
openssl genrsa -out SYRCB_BANK_01.pem 2048
openssl req -new -key SYRCB_BANK_01.pem -out SYRCB_BANK_01.csr
openssl ca -in SYRCB_BANK_01.csr -out SYRCB_BANK_01.crt -cert CA_SYRCB_Root.crt -keyfile CA_SYRCB_Root.pem -days 1826 -policy policy_anything
openssl pkcs12 -export -inkey SYRCB_BANK_01.pem -in SYRCB_BANK_01.crt -out SYRCB_BANK_01.pfx
keytool -importkeystore -srckeystore SYRCB_BANK_01.pfx -destkeystore SYRCB_BANK_01.jks -srcstoretype PKCS12 -deststoretype JKS
查询私钥的.jks文件的信息:keytool -list -v -keystore SYRCB_BANK_01.jks -storepass 密码