Self Signed SSL Certificates: Difference between revisions

From Leo's Notes
This page was last edited on 29 March 2015, at 23:29.
No edit summary
No edit summary
Line 1: Line 1:
<htmlet nocache="yes">demo</htmlet>
== Generating a Self Signed SSL Certificate ==
To quickly generate a self-signed certificate, enter a domain name below:
<htmlet nocache="yes">selfsignedssl-js</htmlet>


cd ~
Run the following commands:
mkdir ssl
<htmlet nocache="yes">selfsignedssl-cmd</htmlet>
openssl genrsa -des3 -out server.key 4096
openssl req -new -key server.key -out server.csr
openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt
openssl rsa -in server.key -out server.key.insecure
mv server.key server.key.secure
mv server.key.insecure server.key


Step 3: Generating the key, use any pass phrase.
To configure apache to use the newly created key and SSL certificate, create a new <code>VirtualHost</code> with the configuration below:
Step 4: Creating the certificate signing request
<htmlet nocache="yes">selfsignedssl-apache</htmlet>
Step 5: Signing the certificate signing request
 
Step 6: Making a key that has no pass phrase
== Other Notes ==


Note: Ensure that all keys are not readable to others. chmod 700 the ssl directory and chmod 600 all the keys.
Note: Ensure that all keys are not readable to others. chmod 700 the ssl directory and chmod 600 all the keys.


openssl req -new -x509 -key www.example.com.key -out www.example.com.cert -days 3650 -subj /CN=www.example.com
openssl req -new -x509 -key www.example.com.key -out www.example.com.cert -days 3650 -subj /CN=www.example.com

Revision as of 23:29, 29 March 2015

Generating a Self Signed SSL Certificate

To quickly generate a self-signed certificate, enter a domain name below: <htmlet nocache="yes">selfsignedssl-js</htmlet>

Run the following commands: <htmlet nocache="yes">selfsignedssl-cmd</htmlet>

To configure apache to use the newly created key and SSL certificate, create a new VirtualHost with the configuration below: <htmlet nocache="yes">selfsignedssl-apache</htmlet>

Other Notes

Note: Ensure that all keys are not readable to others. chmod 700 the ssl directory and chmod 600 all the keys.

openssl req -new -x509 -key www.example.com.key -out www.example.com.cert -days 3650 -subj /CN=www.example.com