Unterschiede
Hier werden die Unterschiede zwischen zwei Versionen angezeigt.
| Beide Seiten der vorigen RevisionVorhergehende ÜberarbeitungNächste Überarbeitung | Vorhergehende Überarbeitung | ||
| linux:ssl [2015/10/19 13:12] – swordfish | linux:ssl [2025/01/25 16:56] (aktuell) – Externe Bearbeitung 127.0.0.1 | ||
|---|---|---|---|
| Zeile 1: | Zeile 1: | ||
| - | Standard: | + | Standard |
| <code bash> | <code bash> | ||
| - | openssl | + | openssl |
| - | openssl req -new -sha512 -key server.key -out server.csr | + | </ |
| - | openssl rsa -in server.key | + | Standard CSR mit alten Key; |
| - | openssl x509 -sha512 -in server.csr | + | <code bash> |
| + | openssl req -out server.csr -new -sha512 -key server.key | ||
| + | </ | ||
| + | |||
| + | Self-signed Certificate: | ||
| + | <code bash> | ||
| + | openssl | ||
| </ | </ | ||
| Zeile 18: | Zeile 24: | ||
| <code bash> | <code bash> | ||
| openssl genrsa -aes256 -out client.key 4096 | openssl genrsa -aes256 -out client.key 4096 | ||
| - | openssl req -new -sha512 -key client.key -out client.csr | + | openssl req -nodes |
| openssl ca -cert ca.crt -keyfile ca.key -out client.crt -in client.csr | openssl ca -cert ca.crt -keyfile ca.key -out client.crt -in client.csr | ||
| openssl pkcs12 -export -inkey client.key -name " | openssl pkcs12 -export -inkey client.key -name " | ||
| Zeile 26: | Zeile 32: | ||
| <code bash> | <code bash> | ||
| openssl genrsa -aes256 -out server.key 4096 | openssl genrsa -aes256 -out server.key 4096 | ||
| - | openssl req -new -key server.key -out server.csr | + | openssl req -nodes |
| openssl x509 -sha512 -req -days 730 -in server.csr -CA ca.crt -CAkey ca.key -set_serial 01 -out server.crt -extfile vpn.conf | openssl x509 -sha512 -req -days 730 -in server.csr -CA ca.crt -CAkey ca.key -set_serial 01 -out server.crt -extfile vpn.conf | ||
| </ | </ | ||
| Zeile 39: | Zeile 45: | ||
| <code bash> | <code bash> | ||
| openssl genrsa -aes256 -out server.key 4096 | openssl genrsa -aes256 -out server.key 4096 | ||
| - | openssl | + | openssl |
| - | openssl req -new -sha512 -key server.key -out server.csr -config | + | |
| </ | </ | ||
| Zeile 47: | Zeile 52: | ||
| [req] | [req] | ||
| distinguished_name = req_distinguished_name | distinguished_name = req_distinguished_name | ||
| - | x509_extensions | + | req_extensions |
| prompt = no | prompt = no | ||
| [req_distinguished_name] | [req_distinguished_name] | ||
| Zeile 54: | Zeile 59: | ||
| L = | L = | ||
| O = Doebl | O = Doebl | ||
| - | OU = VPN | + | OU = WIKI |
| - | CN = vpn.doebl.eu | + | CN = wiki.doebl.eu |
| [v3_req] | [v3_req] | ||
| keyUsage = keyEncipherment, | keyUsage = keyEncipherment, | ||
| Zeile 61: | Zeile 66: | ||
| subjectAltName = @alt_names | subjectAltName = @alt_names | ||
| [alt_names] | [alt_names] | ||
| - | DNS.1 = vpn.doebl.eu | + | DNS.1 = wiki.doebl.eu |
| - | DNS.2 = vpn2.doebl.eu | + | DNS.2 = wiki2.doebl.eu |
| </ | </ | ||
