/etc/pki/CA/crl # sudo mkdir -p /etc/pki/CA/newcerts # sudo mkdir -p /etc/pki/CA/private # sudo chmod 700 /etc/pki/CA/private # sudo touch /etc/pki/CA/index.txt # sudo echo 01 > /etc/pki/CA/serial ೝূہͷ࡞ # sudo openssl req -new -x509 -keyout /etc/pki/CA/private/cakey.pem -out /etc/ pki/CA/certs/cacert.pem -days 3650 Enter PEM pass phrase:ύεϑϨʔζΛೖྗ Verifying - Enter PEM pass phrase:ύεϑϨʔζΛೖྗ ʢதུʣ Country Name (2 letter code) [XX]:JP State or Province Name (full name) []:Hokkaido Locality Name (eg, city) [Default City]:Sapporo Organization Name (eg, company) [Default Company Ltd]:SimSta Organizational Unit Name (eg, section) []:Sim Common Name (eg, your name or your server's hostname) []:rolesanywhere Email Address []:ҙʢෆཁʣ ͋ΔఔదͰ0, $/͓֮͑ͯ͜͏
-out /etc/pki/CA/endentity/endkey.pem 2048 CSRΛ࡞ # sudo openssl req -new -key /etc/pki/CA/endentity/endkey.pem -out /etc/pki/CA/ endentity/endcsr.pem ʢதུʣ Country Name (2 letter code) [XX]:JP State or Province Name (full name) []:Hokkaido Locality Name (eg, city) [Default City]:Sapporo Organization Name (eg, company) [Default Company Ltd]:SimSta Organizational Unit Name (eg, section) []:Sta Common Name (eg, your name or your server's hostname) []:rolesanywhere Email Address []:ҙʢෆཁʣ Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []:ෆཁ An optional company name []:ҙʢෆཁʣ ΄΅ҰॹͰ0, ύεϑϨʔζෆཁ ͋ΔͱΤϥʔʹͳΔ
-cert /etc/pki/CA//certs/cacert.pem -out /etc/pki/CA/ endentity/endcrt.pem -extensions usr_cert Using configuration from /etc/pki/tls/openssl.cnf Enter pass phrase for /etc/pki/CA/private/cakey.pem:CAͷύεϑϨʔζΛೖྗ Check that the request matches the signature Signature ok Certificate Details: ʢதུʣ X509v3 extensions: X509v3 Basic Constraints: CA:FALSE X509v3 Key Usage: Digital Signature, Non Repudiation, Key Encipherment ʢதུʣ Certificate is to be certified until Nov 8 15:09:39 2033 GMT (3650 days) Sign the certificate? [y/n]:y 1 out of 1 certificate requests certified, commit? [y/n]y Write out database with 1 new entries Data Base Updated $"536&Ͱ͋Δ ,FZ6TBHFʹ %*HJUBM4JHOBUVF