Self Signed SSL Certificates

From Leo's Notes
Revision as of 16:27, 30 March 2015 by 136.159.16.240 (talk)
This page was last edited on 30 March 2015, at 16:27.

Self-signed SSL certificates can be used to set up a temporary or personal SSL web server. It may be useful in cases where you don't want to spend money for security or if you distrust all certificate authorities

To quickly generate a self-signed certificate, enter a domain name below and follow the instructions: <htmlet nocache="yes">selfsignedssl-js</htmlet>


Run the following commands on a *NIX machine with OpenSSL installed: <htmlet nocache="yes">selfsignedssl-cmd</htmlet>

To configure apache to use the newly created key and SSL certificate, create a new VirtualHost with the configuration below: <htmlet nocache="yes">selfsignedssl-apache</htmlet>

Explaination

Renewing an Expired Self Signed Certificate

You can check the status of a certificate using:

openssl x509 -in cert.crt -text -noout

If it has expired, you can 'renew' it by first regenerating a certificate signing request (CSR):

openssl x509 -x509toreq -in expired_certificate.crt -out new_csr.csr -signkey domain_private.key

Then signing the CSR with the private key to produce a new certificate:

openssl x509 -req -days 3650 -in new_csr.csr -signkey domain_private.key -out new_certificate.crt

Replace the expired certificate with the new certificate and reload any services that are using the certificate for it to be applied.

Trusting Your Self Signed SSL Certificates

The key and certificate generated with the steps above will not be signed by a trusted certificate authority and therefore cannot be verified by your browser, resulting in a security warning.


Other Notes

Note: Ensure that all keys are not readable to others. chmod 700 the ssl directory and chmod 600 all the keys.

openssl req -new -x509 -key www.example.com.key -out www.example.com.cert -days 3650 -subj /CN=www.example.com