Self Signed SSL Certificates: Difference between revisions

From Leo's Notes
This page was last edited on 7 February 2022, at 02:39.
No edit summary
m Reverted edits by 174.241.28.194 (talk) to last revision by Leo
Tag: Rollback
 
(10 intermediate revisions by 3 users not shown)
Line 1: Line 1:
__NOTOC__
Self signed SSL certificates can be generated using [[OpenSSL]].
Self-signed SSL certificates can be used to set up a temporary or personal SSL web server. It may be useful in cases where you don't want to spend money for security or if you distrust all certificate authorities


To quickly generate a self-signed certificate, enter a domain name below and follow the instructions:
== Steps ==
<htmlet nocache="yes">selfsignedssl-js</htmlet>
=== Private Key ===
Generate a new private key. The output will be a Privacy-Enhanced Mail (PEM) format.
{{highlight|lang=terminal|code=
## Generate a new private key
# openssl genrsa -out server.key 4096
}}


=== Certificate Signing Request ===
Generate the certificate signing request.
{{highlight|lang=terminal|code=
# openssl req -new -sha256 \
        -key server.key \
        -subj "/C=CA/ST=Alberta/O=Steamr/CN=steamr.com" \
        -reqexts SAN \
        -extensions SAN \
        -config <(cat /etc/ssl/openssl.cnf <(printf "[SAN]\nsubjectAltName=DNS:x.steamr.com,DNS:y.steamr.com")) \
        -out server.csr
}}


Run the following commands on a *NIX machine with OpenSSL installed:
The {{code|-subj}} value contains:
<htmlet nocache="yes">selfsignedssl-cmd</htmlet>
{| class="wikitable"
! Field !! Description !! Example
|-
| C || Country - The 2 letter International Standards Organization ISO abbreviation for your country || CA
|-
| ST || State - The state or province of your organization || Alberta
|-
| O || Organization - The legal name of the organization || Steamr Corp.
|-
| CN || Common Name - The fully qualified domain name for the certificate || steamr.com
|}


To configure apache to use the newly created key and SSL certificate, create a new <code>VirtualHost</code> with the configuration below:
Additionally, the {{code|[SAN]}} section passed in through the {{code|-config}} flag is used to define any SANs the certificate should have and can be removed if unneeded.
<htmlet nocache="yes">selfsignedssl-apache</htmlet>


=== Explaination ===
You can verify your CSR using:
{{highlight|lang=terminal|code=
# openssl req -noout -text -in server.csr
}}


== Renewing an Expired Self Signed Certificate ==
After you have verified your CSR, you can either continue to self sign with the next step, or submit it to a CA to purchase a SSL certificate.
You can check the status of a certificate using:
openssl x509 -in cert.crt -text -noout


If it has expired, you can 'renew' it by first regenerating a certificate signing request (CSR):
=== Signing ===
openssl x509 -x509toreq -in expired_certificate.crt -out new_csr.csr -signkey domain_private.key
Sign your certificate signing request.
{{highlight|lang=terminal|code=
# openssl x509 \
        -req \
        -days 730 \
        -extfile <(printf "subjectAltName=DNS:x.steamr.com,DNS:y.steamr.com") \
        -signkey server.key \
        -in server.csr \
        -out server.crt
}}
The {{code|-days}} value defines the number of days the certificate will be valid for from the time of signing. If not given, a default of 30 days will be used.
 
Any SANs will also need to be passed through using the {{code|-extfile}} flag.
 
You can verify the signed certificate by running:
{{highlight|lang=terminal|code=
# openssl x509 -noout -text -in server.crt
}}
 
=== Renewing ===
If the certificate has expired, you can 'renew' it by first regenerating a certificate signing request (CSR):
 
{{highlight|lang=terminal|code=
# openssl x509 -x509toreq -in expired_certificate.crt -out new_csr.csr -signkey domain_private.key
}}


Then signing the CSR with the private key to produce a new certificate:
Then signing the CSR with the private key to produce a new certificate:
openssl x509 -req -days 3650 -in new_csr.csr -signkey domain_private.key -out new_certificate.crt
{{highlight|lang=terminal|code=
# openssl x509 -req -days 3650 -in new_csr.csr -signkey domain_private.key -out new_certificate.crt
}}


Replace the expired certificate with the new certificate and reload any services that are using the certificate for it to be applied.
Replace the expired certificate with the new certificate and reload any services that are using the certificate for it to be applied.


== Trusting Your Self Signed SSL Certificates ==
== Trusting Your Self Signed SSL Certificates ==
The key and certificate generated with the steps above will not be signed by a trusted certificate authority and therefore cannot be verified by your browser, resulting in a security warning.
The key and certificate generated with the steps above will not be signed by a trusted certificate authority and therefore cannot be verified by your browser, resulting in a security warning. To get around this, you can add your certificate directly into your browser or operating system's list of trusted certificate authorities.
 


== Other Notes ==


Note: Ensure that all keys are not readable to others. chmod 700 the ssl directory and chmod 600 all the keys.
== See Also ==
* [[OpenSSL]]
* https://www.sslshopper.com/article-most-common-openssl-commands.html


openssl req -new -x509 -key www.example.com.key -out www.example.com.cert -days 3650 -subj /CN=www.example.com
{{Navbox Linux}}[[Category:Linux]]
[[Category:Certificates]]{{Navbox Certificates}}

Latest revision as of 02:39, 7 February 2022

Self signed SSL certificates can be generated using OpenSSL.

Steps

Private Key

Generate a new private key. The output will be a Privacy-Enhanced Mail (PEM) format.

## Generate a new private key
# openssl genrsa -out server.key 4096

Certificate Signing Request

Generate the certificate signing request.

# openssl req -new -sha256 \
        -key server.key \
        -subj "/C=CA/ST=Alberta/O=Steamr/CN=steamr.com" \
        -reqexts SAN \
        -extensions SAN \
        -config <(cat /etc/ssl/openssl.cnf <(printf "[SAN]\nsubjectAltName=DNS:x.steamr.com,DNS:y.steamr.com")) \
        -out server.csr

The -subj value contains:

Field Description Example
C Country - The 2 letter International Standards Organization ISO abbreviation for your country CA
ST State - The state or province of your organization Alberta
O Organization - The legal name of the organization Steamr Corp.
CN Common Name - The fully qualified domain name for the certificate steamr.com

Additionally, the [SAN] section passed in through the -config flag is used to define any SANs the certificate should have and can be removed if unneeded.

You can verify your CSR using:

# openssl req -noout -text -in server.csr

After you have verified your CSR, you can either continue to self sign with the next step, or submit it to a CA to purchase a SSL certificate.

Signing

Sign your certificate signing request.

# openssl x509 \
        -req \
        -days 730 \
        -extfile <(printf "subjectAltName=DNS:x.steamr.com,DNS:y.steamr.com") \
        -signkey server.key \
        -in server.csr \
        -out server.crt

The -days value defines the number of days the certificate will be valid for from the time of signing. If not given, a default of 30 days will be used.

Any SANs will also need to be passed through using the -extfile flag.

You can verify the signed certificate by running:

# openssl x509 -noout -text -in server.crt

Renewing

If the certificate has expired, you can 'renew' it by first regenerating a certificate signing request (CSR):

# openssl x509 -x509toreq -in expired_certificate.crt -out new_csr.csr -signkey domain_private.key

Then signing the CSR with the private key to produce a new certificate:

# openssl x509 -req -days 3650 -in new_csr.csr -signkey domain_private.key -out new_certificate.crt

Replace the expired certificate with the new certificate and reload any services that are using the certificate for it to be applied.

Trusting Your Self Signed SSL Certificates

The key and certificate generated with the steps above will not be signed by a trusted certificate authority and therefore cannot be verified by your browser, resulting in a security warning. To get around this, you can add your certificate directly into your browser or operating system's list of trusted certificate authorities.


See Also