Self Signed SSL Certificates: Difference between revisions
No edit summary |
No edit summary |
||
| Line 4: | Line 4: | ||
<htmlet nocache="yes">selfsignedssl-js</htmlet> | <htmlet nocache="yes">selfsignedssl-js</htmlet> | ||
On a computer with OpenSSL installed, run the following commands | On a computer with OpenSSL installed, run the following commands individually since you will be prompted for a secure password: | ||
<htmlet nocache="yes">selfsignedssl-cmd</htmlet> | <htmlet nocache="yes">selfsignedssl-cmd</htmlet> | ||
Revision as of 23:54, 29 March 2015
Self-signed SSL certificates can be used to set up a temporary or personal SSL web server. It may be useful in cases where you don't want to spend money for security or if you distrust all certificate authorities
To quickly generate a self-signed certificate, enter a domain name below and follow the instructions: <htmlet nocache="yes">selfsignedssl-js</htmlet>
On a computer with OpenSSL installed, run the following commands individually since you will be prompted for a secure password: <htmlet nocache="yes">selfsignedssl-cmd</htmlet>
To configure apache to use the newly created key and SSL certificate, create a new VirtualHost with the configuration below:
<htmlet nocache="yes">selfsignedssl-apache</htmlet>
Trusting Your Self Signed SSL Certificates
The key and certificate generated with the steps above will not be signed by a trusted certificate authority and therefore cannot be verified by your browser, resulting in a security warning.
Other Notes
Note: Ensure that all keys are not readable to others. chmod 700 the ssl directory and chmod 600 all the keys.
openssl req -new -x509 -key www.example.com.key -out www.example.com.cert -days 3650 -subj /CN=www.example.com