编辑: 会说话的鱼 | 2014-10-12 |
若此凭证欲使用在https,则必须填网址. Email Address []:[email protected] Please enter the following '
extra'
attributes to be sent with your certificate request A challenge password []:[password] An optional company name []:[company] #以上两项可随意输入即可. 产生使用者之凭证. ~/openssl/bin/openssl ca -config ~/openssl/ssl/openssl.cnf \ -policy policy_anything -out islab_cert.pem -infiles islab_req.pem Using configuration from /home/blave/openssl/ssl/openssl.cnf Enter pass phrase for /home/blave/openssl/ssl/misc/demoCA/private/cakey.pem:[输入CA通行码] Check that the request matches the signature Signature ok Certificate Details: Serial Number:
1 (0x1) Validity Not Before: Feb
24 14:34:58
2005 GMT Not After : Feb
22 14:34:58
2015 GMT Subject: countryName = TW stateOrProvinceName = Taiwan localityName = Taichung organizationName = THU organizationalUnitName = ISLAB commonName = [email protected] emailAddress = [email protected] X509v3 extensions: X509v3 Basic Constraints: CA:FALSE Netscape Comment: OpenSSL Generated Certificate X509v3 Subject Key Identifier: EC:88:66:DE:FF:79:CE:81:C2:EE:93:BF:9A:65:92:3B:AC:2C:CD:7E X509v3 Authority Key Identifier: keyid:37:AA:42:CF:FA:D9:73:C7:80:E5:0C:E2:9F:7B:95:86:40:66:72:C5 DirName:/C=TW/ST=Taiwan/L=Taichung/O=Tung-hai University/OU=ISLAB/CN=ISLAB_CA/[email protected] serial:00 Certificate is to be certified until Feb
22 14:34:58
2015 GMT (3650 days) Sign the certificate? [y/n]:y
1 out of
1 certificate requests certified, commit? [y/n]y Write out database with
1 new entries Data Base Updated 检查凭证是否产生. cd ~/openssl/ssl/misc/demoCA ls cacert.pem crl index.txt.attr islab_cert.pem islab_req.pem privat........