Portál AbcLinuxu, 10. května 2025 05:28

Dotaz: Generovani SSL Certs. pro apache

7.2.2007 13:32 Johny01
Generovani SSL Certs. pro apache
Přečteno: 302×
Odpovědět | Admin
Ahoj,


takto nejak generuji SSL cert. pro apache, mam ovsem problem, pri poslendim prikazu (openssl x509 -req -days 360...) jsem vyzvan k zadani ruznejch veci. Nicmene nejsem tazan na FQDN, tedy certifikat neobsahuje vubec info, na jake domene jede. Dusledkem toho to neni moc ok... Prosim, jak do certifikatu dostanu i domenu, pro kteoru ten cert. vystavuji??


openssl genrsa -des3 -rand file1:file2:file3:file4:file5 -out adam.key 1024
openssl rsa -in adam.key -out adam.pem
openssl req -new -key adam.key -out adam.csr
openssl x509 -req -days 360 -in adam.csr -signkey adam.key -out adam.crt


prikladam kus kodu, jak to generuji...


openssl req -new -key adam.key -out adam.csr
Enter pass phrase for adam.key:
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [AU]:CS
State or Province Name (full name) [Some-State]:Czech Republic
Locality Name (eg, city) []:Prague
Organization Name (eg, company) [Internet Widgits Pty Ltd]:ABC s.r.o.
Organizational Unit Name (eg, section) []:
Common Name (eg, YOUR name) []:
Email Address []:

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

a zde je, obsah certifikatu.. :(

burn:/etc/apache2/ssl# openssl req -noout -text -in adam.csr
Certificate Request:
    Data:
        Version: 0 (0x0)
        Subject: C=CS, ST=Czech Republic, L=Prague, O=ABC s.r.o.
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (1024 bit)
                Modulus (1024 bit):
                    00:d4:77:7e:af:b1:ea:84:20:d0:ba:21:11:08:f2:
                    76:a8:3c:80:69:ce:1e:c7:57:d2:b7:ea:59:b6:21:
                    82:ef:d0:72:e3:22:7b:42:ba:2e:af:64:fc:db:f8:
                    04:cb:df:65:4e:c2:9c:a5:04:b1:5a:3c:ed:09:df:
                    9d:30:62:2e:7d:59:fd:da:c2:49:89:a9:a8:a6:0b:
                    e2:ba:0c:39:dc:d6:23:c3:35:6c:53:cb:e0:a0:7f:
                    29:cc:c0:36:30:51:71:24:a1:e0:f7:52:71:c7:70:
                    ed:c5:88:dd:fd:af:3c:68:9b:1b:3b:5a:02:87:4a:
                    a6:e5:c2:5f:3a:d9:b6:c9:d1
                Exponent: 65537 (0x10001)
        Attributes:
            a0:00
    Signature Algorithm: sha1WithRSAEncryption
        3b:d8:02:7d:3f:e1:b8:ac:93:01:49:65:46:e6:13:6e:d8:11:
        95:6d:34:1c:3e:fc:6b:aa:de:fa:f5:38:9d:7e:a8:72:8f:ae:
        31:04:b5:19:8a:3c:77:6f:b3:f3:cd:b3:84:bd:02:73:c0:7b:
        12:54:65:79:c9:84:e7:1f:12:3a:55:39:57:13:4c:70:57:c8:
        04:8b:51:4d:2d:79:c1:7f:7c:8c:d4:1e:ca:31:48:cd:91:00:
        3f:5e:75:02:c9:1f:20:41:ab:28:9d:f2:2c:ad:1e:27:78:ad:
        86:7a:52:0f:db:76:50:39:15:bb:e1:64:34:96:b0:0d:d2:0a:
        b1:10

Nástroje: Začni sledovat (1) ?Zašle upozornění na váš email při vložení nového komentáře.

Odpovědi

7.2.2007 14:12 HonzaH
Rozbalit Rozbalit vše Re: Generovani SSL Certs. pro apache
Odpovědět | | Sbalit | Link | Blokovat | Admin
> Common Name (eg, YOUR name) []:

Zduraznene "YOUR" trochu napovi, ale take jsem dlouho hledal. Tedy CommonName zadavas jako domenu, kde dany certifikat bude.
7.2.2007 14:17 Buki
Rozbalit Rozbalit vše Re: Generovani SSL Certs. pro apache
resp. ne domenu, ale FQDN toho stroje/virt. webu/....

Založit nové vláknoNahoru

Tiskni Sdílej: Linkuj Jaggni to Vybrali.sme.sk Google Del.icio.us Facebook

ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.