centos 配置CA

赛题

CA

  • CA根证书路径/CA/cacert.pem;
  • 签发数字证书,颁发者信息:

国家 = CN

单位 =  Inc

组织机构 = www.skills.com

公用名 = Skill Global Root CA

  • 创建用户组ldsgp ,将zsuser、lsusr、wuusr添加到组内。

1.修改根证书存放目录

vim /etc/pki/tls/openssl.cnf 
42 dir             = /CA           # Where everything is kept
50 certificate     = $dir/cacert.pem       # The CA certificate

2.创建根证书存放目录

[root@rserver ~]# cp -ra /etc/pki/CA/ /CA
[root@rserver CA]# touch {index.txt,serial}
[root@rserver CA]# echo 01 > serial

3.创建根证书

创建私钥

[root@rserver CA]# openssl genrsa -out private/cakey.pem
Generating RSA private key, 2048 bit long modulus
.....................................+++
.........................................+++
e is 65537 (0x10001)

生成cacert.pem根证书

[root@rserver CA]# openssl req -new -x509 -key private/cakey.pem -out cacert.pem
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [XX]:CN
State or Province Name (full name) []:China
Locality Name (eg, city) [Default City]:GuangDong
Organization Name (eg, company) [Default Company Ltd]:skills
Organizational Unit Name (eg, section) []:Inc
Common Name (eg, your name or your server's hostname) []:Skill Global Root CA
Email Address []:

4.测试

[root@rserver CA]# openssl x509 -text -in /CA/cacert.pem -noout | grep Subject
        Subject: C=CN, ST=China, O=skills, OU=Inc, CN=Skill Global Root CA
        Subject Public Key Info:
            X509v3 Subject Key Identifier: 
[root@rserver CA]# 

  • 8
    点赞
  • 6
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

迟今天学习了吗

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值