1.创建根秘钥 openssl genrsa -outca.key 20482.创建根证书 openssl req -new -x509 -days 36500 -sha256 -keyca.key -outopenas.crt -subj "/C=CN/ST=Jiangsu/L=Nanjing/O=HuaweiCA/OU=112.13.167.7"3.创建SSL证书私匙 openssl genrsa -outserver.key 2048位4.建立SSL证书 openssl req -new -sha256 -keyserver.key -outserver.csr -subj "/C=CN/ST=Jiangsu/L=Nanjing/O=HuaweiCA/OU=112.13.167.7/CN=112.13.167.7"5. mkdir demoCA cd demoCA mkdir newcerts touchindex.txti: echo ‘01‘ > serial cd ..6.用CA根证书签署SSL自建证书 openssl ca -md sha256 -inserver.csr -outserver.crt -certopenas.crt -keyfileca.key 7.openssl pkcs12 -export -outcertificate.pfx -inkeyprivateKey.key -incertificate.crt 8.keytool -importkeystore -srckeystore subcert.p12 -destkeystoresubcert.jks -srcstoretype pkcs12 新建keystore keytool -genkey -alias newkeystore -keyalg RSA -validity 20000 -keystore newkeystore 将证书导入keystore keytool -import -fileopenas.crt -keystore newkeystore
时间: 2024-10-05 08:26:14