安装服务
root@debian:/etc/chrony# apt install -y openssl
配置文件
root@debian:/etc/chrony# cd /etc/ssl/
root@debian:/etc/ssl# ls
certs openssl.cnf private
root@debian:/etc/ssl# vim openssl.cnf
创建目录
root@debian:/etc/ssl# cd CA/
root@debian:/etc/ssl/CA# ls -l
total 0
root@debian:/etc/ssl/CA# mkdir certs
root@debian:/etc/ssl/CA# mkdir crl
root@debian:/etc/ssl/CA# touch index.txt
root@debian:/etc/ssl/CA# mkdir newcerts
root@debian:/etc/ssl/CA# echo "01" > serial
root@debian:/etc/ssl/CA# ls -l
total 16
drwxr-xr-x 2 root root 4096 Apr 30 02:55 certs
drwxr-xr-x 2 root root 4096 Apr 30 02:56 crl
-rw-r--r-- 1 root root 0 Apr 30 02:57 index.txt
drwxr-xr-x 2 root root 4096 Apr 30 02:57 newcerts
-rw-r--r-- 1 root root 3 Apr 30 02:58 serial
root@debian:/etc/ssl/CA# mkdir private
root@debian:/etc/ssl/CA# openssl genrsa -out private/cakey.pem
Generating RSA private key, 2048 bit long modulus (2 primes)
...........................+++++
....+++++
e is 65537 (0x010001)
root@debian:/etc/ssl/CA# openssl req -new -x509 -key private/cakey.pem -out cacert.pem
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter