Self Signed SSL Certificates
Self signed SSL certificates can be generated using OpenSSL.
Steps
Private Key
Generate a new private key. The output will be a Privacy-Enhanced Mail (PEM) format.
## Generate a new private key
# openssl genrsa -out server.key 4096
Certificate Signing Request
Generate the certificate signing request.
# openssl req -new -sha256 \
-key server.key \
-subj "/C=CA/ST=Alberta/O=Steamr/CN=steamr.com" \
-reqexts SAN \
-extensions SAN \
-config <(cat /etc/ssl/openssl.cnf <(printf "[SAN]\nsubjectAltName=DNS:x.steamr.com,DNS:y.steamr.com")) \
-out server.csr
The -subj value contains:
| Field | Description | Example |
|---|---|---|
| C | Country - The 2 letter International Standards Organization ISO abbreviation for your country | CA |
| ST | State - The state or province of your organization | Alberta |
| O | Organization - The legal name of the organization | Steamr Corp. |
| CN | Common Name - The fully qualified domain name for the certificate | steamr.com |
Additionally, the [SAN] section passed in through the -config flag is used to define any SANs the certificate should have and can be removed if unneeded.
You can verify your CSR using:
# openssl req -noout -text -in server.csr
After you have verified your CSR, you can either continue to self sign with the next step, or submit it to a CA to purchase a SSL certificate.
Signing
Sign your certificate signing request.
# openssl x509 \
-req \
-days 730 \
-extfile <(printf "subjectAltName=DNS:x.steamr.com,DNS:y.steamr.com") \
-signkey server.key \
-in server.csr \
-out server.crt
The -days value defines the number of days the certificate will be valid for from the time of signing. If not given, a default of 30 days will be used.
Any SANs will also need to be passed through using the -extfile flag.
You can verify the signed certificate by running:
# openssl x509 -noout -text -in server.crt
Renewing
If the certificate has expired, you can 'renew' it by first regenerating a certificate signing request (CSR):
# openssl x509 -x509toreq -in expired_certificate.crt -out new_csr.csr -signkey domain_private.key
Then signing the CSR with the private key to produce a new certificate:
# openssl x509 -req -days 3650 -in new_csr.csr -signkey domain_private.key -out new_certificate.crt
Replace the expired certificate with the new certificate and reload any services that are using the certificate for it to be applied.
Trusting Your Self Signed SSL Certificates
The key and certificate generated with the steps above will not be signed by a trusted certificate authority and therefore cannot be verified by your browser, resulting in a security warning. To get around this, you can add your certificate directly into your browser or operating system's list of trusted certificate authorities.
See Also
- OpenSSL
- https://www.sslshopper.com/article-most-common-openssl-commands.html
Various Linux Notes - /etc/fstab
- Access.conf
- ACL
- Apache Proxy to Internal Server
- APM X-C1 (Mustang)
- ARP
- Authselect
- Bash Scripting
- Blockparser
- Booting Linux without a Graphics Card
- Building Container Images
- Burning CD/DVD in Linux
- Clear RAID Signatures on Linux
- Cobbler
- Colorized Terminal Outputs
- Compiling MIPS
- Configure Sendmail
- CPanel
- CPanel Fork Bomb Protection
- CPU Frequency Scaling
- Create a Linux User with an Empty Password
- Cron and PAM Issues
- Dell OpenManage
- Diff Two Command Outputs
- DirectAdmin
- Disable Filesystem Check on Startup
- DNS Ad Blocker
- Driver Disk
- Drop caches
- End / Home keys don't work in Terminal
- Entropy in the Linux Kernel
- Entropy Source using RTL-SDR
- Exit Codes
- Extract .exe Resources with dd
- File Attributes
- Fixing ixgbe unsupported SFP+ module type was detected
- Get Active Linux Virtual Console
- Getting Hardware UUID
- Hosts.deny
- How to change Linux desktop user directories
- How to hot-swap SATA disks on Linux
- HP Smart Storage Administrator
- Hyper-threading
- IBM Spectrum Archive
- IBM Spectrum Protect
- IBM Tape
- IBM Tape Diagnostic Tool
- InterWorx
- Kerberize NFS
- Kerberize SSH
- Linux Clustering
- Linux Fonts
- Linux Namespaces
- Linux Network Interface Naming
- Linux Nvidia Driver
- Linux Process Accounting
- Linux Uptime in Seconds
- Linux UTF-8 Font
- Mainline Kernel on CentOS 7
- Missing Fonts
- Mod fastcgi Install on Apache 2 / cPanel
- Mod fcgid
- Monitoring network traffic in Linux
- Mounting / Unmounting KVM Image
- Mounting Samba (CIFS) shares
- Multiple Networks on Linux
- MySQL Database with Hash Sign
- No Console Output
- Number of Files Opened
- Open OnDemand
- Packing and unpacking initrd
- PAM Issues
- Partition Alignment
- Patching a binary file with dd
- Perl Module Location
- Raspberry Pi
- Red Hat kickstart
- Red Hat to Debian
- Reverse SSH Tunnel
- Ruby on Rails under cPanel
- Rutorrent + rtorrent Installation Guide on CentOS 6.4
- Self Signed SSL Certificates
- Service Management
- Sick Beard
- StartSSL Free Certificate
- Symlink
- Taking a Screenshot in X11
- Timezone
- Tor
- TOR Transparent Proxy
- Traefik
- Troubleshooting a Slow Linux System
- Turning on swap with a page file
- Udev Rules
- Verify SSL Certificate matches Private Key
- VMware Workstation
- Webcam
- X Display Manipulation
- X Forwarding
Linux Tools and Utilites - Anaconda
- Ansible
- Aria2
- Autofs
- Awk
- Badblocks
- Bash Shell
- Binwalk
- Bosh
- Ceph
- Chntpw
- Chrony
- Clonezilla
- Cloud-init
- CloudStack
- Column
- Cron
- Curl
- Cvs2git
- Date
- Dbus
- Dd
- Dm-crypt
- Dovecot
- DRBD
- ElasticSearch
- Enroot
- Environment Module
- Envsubst
- Fail2ban
- FFmpeg
- Find
- Firecracker
- Flashrom
- Foreman
- FortiClient
- Fswebcam
- Galaxy
- Git
- Gnome
- Gobetween
- GPFS
- Grafana
- Grub
- Hdparm
- Home Assistant
- How to disable SELinux
- Htaccess
- Infiniband
- InfluxDB
- InfluxDB 1.x
- Insert a kickstart file into a iso image
- Inspircd
- IOzone
- Iperf3
- Ipmitool
- Irqbalance
- John The Ripper
- Lightdm
- Lm sensors
- Logrotate
- LSF
- LVM
- Lynx
- Mailx
- Md5sum
- Mdadm
- Midnight Commander
- Motion
- Mount
- Mutt
- Nomad
- OpenLDAP
- Openocd
- OpenSSL
- OpenVPN
- Packer
- PHP
- Pi-hole
- Postgres
- PowerBroker Identity Service
- Proxmox
- Pueue
- PulseAudio
- Puppet
- Quota
- Red Hat Satellite
- Restic
- Rsync
- Rtorrent
- Ruby
- Sabnzbd
- Sage
- Samba
- Screen
- Sed
- SELinux
- Sendmail
- Shell Configs
- Singularity
- Sleep
- Slurm
- SMART
- Sonarr
- Sqlite
- SquashFS
- Squid
- SSH
- Steam
- Stoken
- Strace
- Sudo
- Sync
- Sysctl
- Syslog
- Sysrq
- System Security Services Daemon (SSSD)
- Systemd
- Tar
- Tcsh
- Telegraf
- Terraform
- Thttpd
- Tmux
- Tomcat
- Top
- Umask
- Unix2dos
- Vim
- Virsh
- Virt-customize
- VirtualBox
- VirtualGL
- Visidata
- Vnstat
- Weechat
- Wget
- XFS
- Youtube-dl
- ZFS
- Zram
Package Management Linux Distributions Networking - Blazemeter
- CSF/LFD
- Exim
- Firewall
- FreeIPA
- Get DHCP Network Settings
- IP Aliasing
- Ipset
- IPTables
- IPv6
- IPXE
- Link Aggregation
- Linux Network Namespaces
- MTU
- Net-tools to iproute2
- Netcat
- Open vSwitch
- OpenWRT
- Postfix
- Raspberry Pi Torified Wifi
- Socat
- Static Routes
- StrongSwan
- Tcpdump
- Traffic Forwarder using IPTables
- Wi-Fi
- WireGuard
Containers