Generowanie kluczy SSL

Generowanie CA (wystarczy raz):

  1. openssl genrsa -des3 -out my-ca.key 2048
  2. openssl req -new -x509 -days 3650 -key my-ca.key -out my-ca.crt
  3. openssl x509 -in my-ca.crt -text -noout

Podpisywanie strony:
Common Name = host.domain.tld

  1. openssl genrsa -des3 -out server.key 1024
  2. openssl req -new -key server.key -out server.csr
  3. openssl x509 -req -in server.csr -out server.crt -sha1 -CA my-ca.crt -CAkey my-ca.key -CAcreateserial -days 3650
  4. openssl x509 -in server.crt -text -noout
  5. openssl rsa -in server.key -out server.pem

W apache używamy server.pem i server.crt