直接回答:自建 CA 就是先用 openssl 生成一对根密钥和根证书,再用它给各服务的 CSR 签名;现代浏览器要求证书里必须有 SAN 扩展,只写 CN 已经不被信任。

一、生成CA

1、生成CA的key

1
openssl genrsa -out ca.key 4096

2、生成CA证书

1
2
3
4
5
openssl req -new -x509 -utf8 \
-days ${VALID_DAYS} \
-key ca.key \
-out ca.crt \
-subj /C=CN/ST=河南省/L=郑州市/O=某公司/OU=六氟化硫权限管理系统/CN=物联网事业部测试用根证书/emailAddress=example@example.com

二、生成签证

1
2
3
4
5
6
7
8
9
10
11
12
13
14
# san.cnf
[req]
default_bits = 4096
default_md = sha256
distinguished_name = req_distinguished_name
req_extensions = v3_req
[req_distinguished_name]
[v3_req]
basicConstraints = CA:FALSE
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
subjectAltName = @alt_names
[alt_names]
DNS.1 = *.example.com
IP.1 = 192.168.1.100

第一步: 生成服务端key

1
openssl genrsa -out server.key 4096

第二步:生成签证请求,这一步需要修改scan的内容,ip那一部分就是服务器IP地址,ou是组织单位,可以改为系统名字

1
openssl req -new -sha256 -key server.key -out server.csr -subj /C=CN/ST=HeNan/L=ZhenZhou/O=Relations/OU=SF6/CN=192.168.1.100/emailAddress=example@example.com  -config san.cnf

第三步:签发证书

set_serial是证书编号,-in是第二步产生的结果

1
2
3
4
5
6
7
8
openssl x509 -req  -days 370 -in server.csr \
-CA ca.crt \
-CAkey ca.key \
-set_serial 20210826104044 \
-out server.crt \
-sha256 \
-extfile san.cnf \
-extensions v3_req

这篇笔记整理自我自己的实践记录,如果做法有出入,或者你踩过别的坑,欢迎到留言板一起聊聊。

站内搜索

没有找到内容!