4 246
modifications
(→V2) |
|||
Ligne 244 : | Ligne 244 : | ||
<pre>openssl req -new -newkey rsa:2048 -keyout private/cakey.pem -out careq.pem -config /etc/ssl/openssl.cnf </pre> | <pre>openssl req -new -newkey rsa:2048 -keyout private/cakey.pem -out careq.pem -config /etc/ssl/openssl.cnf </pre> | ||
<pre>openssl ca - | <pre>openssl ca -rand_serial -out cacert.pem -days 365 -keyfile private/cakey.pem -selfsign -config /etc/ssl/openssl.cnf -infiles careq.pem </pre> | ||
- | -rand-serial est important et permet d'initialiser un sérial aléatoire de 128 bits. | ||
see https://www.phildev.net/ssl/creating_ca.html | see https://www.phildev.net/ssl/creating_ca.html |