直接回答:自建 CA 就是先用 openssl 生成一对根密钥和根证书,再用它给各服务的 CSR 签名;现代浏览器要求证书里必须有 SAN 扩展,只写 CN 已经不被信任。
一、生成CA
1、生成CA的key
1
| openssl genrsa -out ca.key 4096
|
2、生成CA证书
1 2 3 4 5
| openssl req -new -x509 -utf8 \ -days ${VALID_DAYS} \ -key ca.key \ -out ca.crt \ -subj /C=CN/ST=河南省/L=郑州市/O=某公司/OU=六氟化硫权限管理系统/CN=物联网事业部测试用根证书/emailAddress=example@example.com
|
二、生成签证
1 2 3 4 5 6 7 8 9 10 11 12 13 14
| # san.cnf [req] default_bits = 4096 default_md = sha256 distinguished_name = req_distinguished_name req_extensions = v3_req [req_distinguished_name] [v3_req] basicConstraints = CA:FALSE keyUsage = nonRepudiation, digitalSignature, keyEncipherment subjectAltName = @alt_names [alt_names] DNS.1 = *.example.com IP.1 = 192.168.1.100
|
第一步: 生成服务端key
1
| openssl genrsa -out server.key 4096
|
第二步:生成签证请求,这一步需要修改scan的内容,ip那一部分就是服务器IP地址,ou是组织单位,可以改为系统名字
1
| openssl req -new -sha256 -key server.key -out server.csr -subj /C=CN/ST=HeNan/L=ZhenZhou/O=Relations/OU=SF6/CN=192.168.1.100/emailAddress=example@example.com -config san.cnf
|
第三步:签发证书
set_serial是证书编号,-in是第二步产生的结果
1 2 3 4 5 6 7 8
| openssl x509 -req -days 370 -in server.csr \ -CA ca.crt \ -CAkey ca.key \ -set_serial 20210826104044 \ -out server.crt \ -sha256 \ -extfile san.cnf \ -extensions v3_req
|
这篇笔记整理自我自己的实践记录,如果做法有出入,或者你踩过别的坑,欢迎到留言板一起聊聊。