Self Signed SSL Certificates: Difference between revisions

From Leo's Notes
This page was last edited on 30 March 2015, at 05:18.
No edit summary
No edit summary
Line 1: Line 1:
Self-signed SSL certificates can be used to set up a temporary or personal SSL web server. It may be useful in cases where you don't want to spend money for security or if you distrust all certificate authorities.
Self-signed SSL certificates can be used to set up a temporary or personal SSL web server. It may be useful in cases where you don't want to spend money for security or if you distrust all certificate authorities


To quickly generate a self-signed certificate, enter a domain name below and follow the instructions below. For an explanation of how it works, please see the sections below.
To quickly generate a self-signed certificate, enter a domain name below and follow the instructions:
<htmlet nocache="yes">selfsignedssl-js</htmlet>
<htmlet nocache="yes">selfsignedssl-js</htmlet>


On a computer with OpenSSL installed, run the following commands individually since you will be prompted for a secure password:
 
Run the following commands on a *NIX machine with OpenSSL installed:
<htmlet nocache="yes">selfsignedssl-cmd</htmlet>
<htmlet nocache="yes">selfsignedssl-cmd</htmlet>


To configure apache to use the newly created key and SSL certificate, create a new <code>VirtualHost</code> with the configuration below:
To configure apache to use the newly created key and SSL certificate, create a new <code>VirtualHost</code> with the configuration below:
<htmlet nocache="yes">selfsignedssl-apache</htmlet>
<htmlet nocache="yes">selfsignedssl-apache</htmlet>
=== Explaination ===


== Trusting Your Self Signed SSL Certificates ==
== Trusting Your Self Signed SSL Certificates ==
The key and certificate generated with the steps above will not be signed by a trusted certificate authority and therefore cannot be verified by your browser, resulting in a security warning.
The key and certificate generated with the steps above will not be signed by a trusted certificate authority and therefore cannot be verified by your browser, resulting in a security warning.
== Intermediate Certificate Authority ==




Line 21: Line 23:


openssl req -new -x509 -key www.example.com.key -out www.example.com.cert -days 3650 -subj /CN=www.example.com
openssl req -new -x509 -key www.example.com.key -out www.example.com.cert -days 3650 -subj /CN=www.example.com
== See Also ==
* https://mozilla.github.io/server-side-tls/ssl-config-generator/

Revision as of 05:18, 30 March 2015

Self-signed SSL certificates can be used to set up a temporary or personal SSL web server. It may be useful in cases where you don't want to spend money for security or if you distrust all certificate authorities

To quickly generate a self-signed certificate, enter a domain name below and follow the instructions: <htmlet nocache="yes">selfsignedssl-js</htmlet>


Run the following commands on a *NIX machine with OpenSSL installed: <htmlet nocache="yes">selfsignedssl-cmd</htmlet>

To configure apache to use the newly created key and SSL certificate, create a new VirtualHost with the configuration below: <htmlet nocache="yes">selfsignedssl-apache</htmlet>

Explaination

Trusting Your Self Signed SSL Certificates

The key and certificate generated with the steps above will not be signed by a trusted certificate authority and therefore cannot be verified by your browser, resulting in a security warning.


Other Notes

Note: Ensure that all keys are not readable to others. chmod 700 the ssl directory and chmod 600 all the keys.

openssl req -new -x509 -key www.example.com.key -out www.example.com.cert -days 3650 -subj /CN=www.example.com