CA重要配置文件:
/etc/pki/tls/openssl.cnf
1.生成私钥
1.1不加密
:(umask 066;openssl genrsa -out private.key 1024)
:(umask 066;openssl genrsa -out /etc/pki/CA/private/cakey.pem 1024)
1.2加密
:(umask 066;openssl genrsa -out private.key -des 1024)
:(umask 066;openssl genrsa -out /etc/pki/CA/private/cakey .pem -des 1024)
1.2.1解密
:openssl rsa -in private.key -out private.key2
2.根据私钥生成公钥
2.1由没有加密的私钥(private.key2)生成公钥(public.key2)
openssl rsa -in private.key2 -pubout -out public.key2
2.2由有加密的私钥(private.key)生成公钥(public.key)
openssl rsa -in private.key -pubout -out public.key
3.生成的公钥与私钥
posted on
2018-09-17 11:12
圆缘
阅读(
17572)
评论()
编辑
收藏
举报