歡迎您光臨本站 註冊首頁

Apache配置SSL證書伺服器傻瓜步驟

←手機掃碼閱讀     火星人 @ 2014-03-09 , reply:0
在Linux Apache OpenSSL中配置SSL安全證書認證是不難的,我的另一篇工作隨記中曾提到[url]http://www.host01.com/article/server/00070002/0621409075193649.htm[/url]中有所有步驟,不過其中的一些描述有點複雜,並且依賴關係也沒有這些嚴格.這裡給出一個傻瓜式步驟,供自己和有心人復用.
首先確保你的Linux有OpenSSL(ls -l /usr/bin/openssl),如果沒有請從[url]http://openssl.org/[/url]下載.
mkdir demoCA
cp /usr/share/ssl/openssl.cnf ./demoCA
vi ./demoCA/openssl.cnf and edit the dir configuration of CA_default from ./demoCA to .
mkdir demoCA/certs
mkdir demoCA/crl
mkdir demoCA/newcerts
mkdir demoCA/private
echo "01" > demoCA/serial
touch demoCA/index.txt
cd demoCA
openssl req -new -x509 -keyout ./private/cakey.pem -out ./cacert.pem -days 3650(password input twice, 該密碼多次用到,HTTPD啟動也須用到, 10年有效期)
Country Name (2 letter code) [GB]:US
State or Province Name (full name) [Berkshire]:CA
Locality Name (eg, city) [Newbury]:San Clara
Organization Name (eg, company) [My Company Ltd]:Cisco
Organizational Unit Name (eg, section) []:WebEx
Common Name (eg, your name or your server's hostname) []:ServerDNSName(最好跟你SERVER名字一樣)
Email Address []:
openssl genrsa -des3 -out server.key 1024
openssl req -new -key server.key -out server.csr
Country Name (2 letter code) [GB]:US
State or Province Name (full name) [Berkshire]:CA
Locality Name (eg, city) [Newbury]:San Clara
Organization Name (eg, company) [My Company Ltd]:Cisco
Organizational Unit Name (eg, section) []:WebEx
Common Name (eg, your name or your server's hostname) []:ServerDNSName


[火星人 ] Apache配置SSL證書伺服器傻瓜步驟已經有408次圍觀

http://coctec.com/docs/linux/show-post-54248.html