浏览代码

create server cert req via openssl

Fabian Peter Hammerle 7 年之前
父节点
当前提交
94fabca132
共有 2 个文件被更改,包括 6 次插入9 次删除
  1. 1 1
      README.md
  2. 5 8
      openssl.conf

+ 1 - 1
README.md

@@ -2,7 +2,7 @@
 
 
 ```sh
 ```sh
 git clone --origin template \
 git clone --origin template \
-    --branch openssl-client \
+    --branch openssl-server \
     https://git.hammerle.me/fphammerle/template-x509-cert-request-generation.git \
     https://git.hammerle.me/fphammerle/template-x509-cert-request-generation.git \
     new-cert-request
     new-cert-request
 ```
 ```

+ 5 - 8
openssl.conf

@@ -4,16 +4,13 @@ distinguished_name = req_distinguished_name
 req_extensions = req_extensions
 req_extensions = req_extensions
 
 
 [ req_distinguished_name ]
 [ req_distinguished_name ]
-C = AT
-CN = Fabian Peter Hammerle
-emailAddress = fabian@hammerle.me
+CN = fabian.hammerle.me
 
 
 [ req_extensions ]
 [ req_extensions ]
 # man x509v3_config
 # man x509v3_config
-subjectAltName = email:fabian@hammerle.me, email:fabian.hammerle@gmail.com
+subjectAltName = critical, DNS:fabian.hammerle.me
 basicConstraints = critical,CA:FALSE
 basicConstraints = critical,CA:FALSE
-keyUsage = digitalSignature
-extendedKeyUsage = clientAuth
-nsCertType = client
-nsComment = client authentication only
+keyUsage = critical, digitalSignature, keyEncipherment
+extendedKeyUsage = serverAuth
+nsCertType = server
 subjectKeyIdentifier = hash
 subjectKeyIdentifier = hash