openssl 生成国密证书
openssl生成证书
-
生成CA私钥
openssl ecparam -genkey -name SM2 -out openssl_ca.key -noout -
证书请求
openssl req -new -key openssl_ca.key -out openssl_ca.req -subj “/CN=openssl.CA.com” -
生成证书
openssl x509 -req -days 3650 -in openssl_ca.req -signkey openssl_ca.key -out openssl_ca.pem -
生成目标私钥
openssl ecparam -genkey -name SM2 -out openssl_dave.key -noout -
证书请求
openssl req -new -key openssl_dave.key -out openssl_dave.req -subj “/CN=I am dave” -
生成证书
openssl x509 -req -days 3650 -in openssl_dave.req -CA openssl_ca.pem -CAkey openssl_ca.key -out openssl_dave.pem -
查看私钥密钥格式ASN.1内容
openssl asn1parse -in openssl_dave.key -
查看证书内容
openssl x509 -in openssl_dave.pem -noout -text