证书之间的相互转换
openssl pkcs12 -in ./keystore.p12 -nokeys -clcerts -out ./keystore.crt
openssl pkcs12 -in ./keystore.p12 -nocerts -nodes -out ./keystore.key
openssl pkcs12 -export -in client.crt -inkey client.key -out client.p12 -name "irving"
openssl pkcs12 -export -in server.crt -inkey server.key -out server.p12 -name "irivng"
openssl x509 -in ca.crt -out ca.cer -outform der
openssl x509 -text -noout -in server.crt
sudo keytool -import -alias matrix -keystore "$JRE/lib/security/cacerts" -storepass changeit -keypass changeit -file ./ca.crt -noprompt
sudo keytool -delete -alias matrix -keystore "$JRE/lib/security/cacerts" -storepass changeit
生成根证书(ca.crt, ca.key),服务端证书(client.p12, client.crt, client.key),客户端证书(server.p12, serv