Update webpage "Documentation - OpenSSL Self-signed Certificate Chain" from version "2.0.0-beta.1" to "3.0.0-beta.1"
This commit is contained in:
parent
f80a219b99
commit
23112c01b3
@ -1,7 +1,7 @@
|
|||||||
<!DOCTYPE html>
|
<!DOCTYPE html>
|
||||||
|
|
||||||
<!-- Inferencium - Website - Documentation - OpenSSL Self-signed Certificate Chain -->
|
<!-- Inferencium - Website - Documentation - OpenSSL Self-signed Certificate Chain -->
|
||||||
<!-- Version: 2.0.0-beta.1 -->
|
<!-- Version: 3.0.0-beta.1 -->
|
||||||
|
|
||||||
<!-- Copyright 2023 Jake Winters -->
|
<!-- Copyright 2023 Jake Winters -->
|
||||||
<!-- SPDX-License-Identifier: BSD-3-Clause -->
|
<!-- SPDX-License-Identifier: BSD-3-Clause -->
|
||||||
@ -16,19 +16,19 @@
|
|||||||
</head>
|
</head>
|
||||||
<body>
|
<body>
|
||||||
<nav class="navbar">
|
<nav class="navbar">
|
||||||
<div><a href="../index.xhtml"><img src="../asset/img/logo-inferencium-no_text.png" width="110px" height="110px"/></a></div>
|
<div><a href="../index.xhtml"><img src="../asset/img/logo-inferencium-no_text.png" width="110" height="110" alt="Inferencium logo"/></a></div>
|
||||||
<div><a href="../index.xhtml" class="title">Inferencium</a></div>
|
<div><a href="../index.xhtml" class="title">Inferencium</a></div>
|
||||||
<div><a href="../about.xhtml">About</a></div>
|
<div><a href="../about.xhtml">About</a></div>
|
||||||
<div><a href="../contact.xhtml">Contact</a></div>
|
|
||||||
<div><a href="../blog.xhtml">Blog</a></div>
|
|
||||||
<div><a href="../documentation.xhtml">Documentation</a></div>
|
<div><a href="../documentation.xhtml">Documentation</a></div>
|
||||||
<div><a href="../source.xhtml">Source</a></div>
|
<div><a href="../source.xhtml">Source</a></div>
|
||||||
<div><a href="../key.xhtml">Key</a></div>
|
|
||||||
<div><a href="../changelog.xhtml">Changelog</a></div>
|
<div><a href="../changelog.xhtml">Changelog</a></div>
|
||||||
|
<div><a href="../blog.xhtml">Blog</a></div>
|
||||||
|
<div><a href="../contact.xhtml">Contact</a></div>
|
||||||
<div><a href="../directory.xhtml">Directory</a></div>
|
<div><a href="../directory.xhtml">Directory</a></div>
|
||||||
|
<div><a href="../key.xhtml">Key</a></div>
|
||||||
</nav>
|
</nav>
|
||||||
|
<h1 id="openssl_selfsigned_certificate_chain"><a href="#openssl_selfsigned_certificate_chain">Documentation - OpenSSL Self-signed Certificate Chain</a></h1>
|
||||||
<section id="introduction">
|
<section id="introduction">
|
||||||
<h1 id="introduction"><a href="#introduction">Documentation - OpenSSL Self-signed Certificate Chain</a></h1>
|
|
||||||
<p>This documentation contains the complete set of commands to create a new OpenSSL
|
<p>This documentation contains the complete set of commands to create a new OpenSSL
|
||||||
self-signed certificate chain with V3 subjectAltName (SAN) extensions enabled. Multiple
|
self-signed certificate chain with V3 subjectAltName (SAN) extensions enabled. Multiple
|
||||||
SANs can be included in a certificate by adding each domain as a comma-delimited string.
|
SANs can be included in a certificate by adding each domain as a comma-delimited string.
|
||||||
@ -40,7 +40,7 @@
|
|||||||
<a href="https://src.inferencium.net/Inferencium/doc/src/branch/stable/security/openssl_selfsigned_certificate_chain.adoc">documentation source code repository</a>.</p>
|
<a href="https://src.inferencium.net/Inferencium/doc/src/branch/stable/security/openssl_selfsigned_certificate_chain.adoc">documentation source code repository</a>.</p>
|
||||||
</section>
|
</section>
|
||||||
<nav id="toc">
|
<nav id="toc">
|
||||||
<h2 id="toc"><a href="#toc">Table of Contents</a></h2>
|
<h2><a href="#toc">Table of Contents</a></h2>
|
||||||
<ul>
|
<ul>
|
||||||
<li><a href="#create_certificate_authority_key">Create Certificate Authority Key</a></li>
|
<li><a href="#create_certificate_authority_key">Create Certificate Authority Key</a></li>
|
||||||
<li><a href="#verify_certificate_authority_key">Verify Certificate Authority Key</a></li>
|
<li><a href="#verify_certificate_authority_key">Verify Certificate Authority Key</a></li>
|
||||||
@ -62,71 +62,71 @@
|
|||||||
</ul>
|
</ul>
|
||||||
</nav>
|
</nav>
|
||||||
<section id="create_certificate_authority_key">
|
<section id="create_certificate_authority_key">
|
||||||
<h2 id="create_certificate_authority_key"><a href="#create_certificate_authority_key">Create Certificate Authority Key</a></h2>
|
<h2><a href="#create_certificate_authority_key">Create Certificate Authority Key</a></h2>
|
||||||
<p><code>openssl genrsa <var><encryption type></var> -out <var><CA key name></var>.pem <var><key size></var></code></p>
|
<p><code>openssl genrsa <var><encryption type></var> -out <var><CA key name></var>.pem <var><key size></var></code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="verify_certificate_authority_key">
|
<section id="verify_certificate_authority_key">
|
||||||
<h2 id="verify_certificate_authority_key"><a href="#verify_certificate_authority_key">Verify Certificate Authority Key</a></h2>
|
<h2><a href="#verify_certificate_authority_key">Verify Certificate Authority Key</a></h2>
|
||||||
<p><code>openssl rsa -noout -text -in <var><CA key name></var>.pem</code></p>
|
<p><code>openssl rsa -noout -text -in <var><CA key name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="create_certificate_authority_certificate">
|
<section id="create_certificate_authority_certificate">
|
||||||
<h2 id="create_certificate_authority_certificate"><a href="#create_certificate_authority_certificate">Create Certificate Authority Certificate</a></h2>
|
<h2><a href="#create_certificate_authority_certificate">Create Certificate Authority Certificate</a></h2>
|
||||||
<p><code>openssl req -new -x509 -days <var><days of validity></var> -extensions v3_ca -key <var><CA key name></var>.pem -out <var><CA certificate name></var>.pem</code></p>
|
<p><code>openssl req -new -x509 -days <var><days of validity></var> -extensions v3_ca -key <var><CA key name></var>.pem -out <var><CA certificate name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="convert_certificate_to_pem_format">
|
<section id="convert_certificate_to_pem_format">
|
||||||
<h2 id="convert_certificate_to_pem_format"><a href="#convert_certificate_to_pem_format">Convert Certificate to PEM Format</a></h2>
|
<h2><a href="#convert_certificate_to_pem_format">Convert Certificate to PEM Format</a></h2>
|
||||||
<p><code>openssl x509 -in <var><CA certificate name></var>.pem -out <var><CA certificate name></var>.pem -outform PEM</code></p>
|
<p><code>openssl x509 -in <var><CA certificate name></var>.pem -out <var><CA certificate name></var>.pem -outform PEM</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="verify_certificate_authority_certificate">
|
<section id="verify_certificate_authority_certificate">
|
||||||
<h2 id="verify_certificate_authority_certificate"><a href="#verify_certificate_authority_certificate">Verify Certificate Authority Certificate</a></h2>
|
<h2><a href="#verify_certificate_authority_certificate">Verify Certificate Authority Certificate</a></h2>
|
||||||
<p><code>openssl x509 -noout -text -in <var><CA certificate name></var>.pem</code></p>
|
<p><code>openssl x509 -noout -text -in <var><CA certificate name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="create_intermediate_certificate_authority_key">
|
<section id="create_intermediate_certificate_authority_key">
|
||||||
<h2 id="create_intermediate_certificate_authority_key"><a href="#create_intermediate_certificate_authority_key">Create Intermediate Certificate Authority Key</a></h2>
|
<h2><a href="#create_intermediate_certificate_authority_key">Create Intermediate Certificate Authority Key</a></h2>
|
||||||
<p><code>openssl genrsa <var><encryption type></var> -out <var><intermediate CA key name></var>.pem <var><key size></var></code></p>
|
<p><code>openssl genrsa <var><encryption type></var> -out <var><intermediate CA key name></var>.pem <var><key size></var></code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="verify_intermediate_certificate_authority_key">
|
<section id="verify_intermediate_certificate_authority_key">
|
||||||
<h2 id="verify_intermediate_certificate_authority_key"><a href="#verify_intermediate_certificate_authority_key">Verify Intermediate Certificate Authority Key</a></h2>
|
<h2><a href="#verify_intermediate_certificate_authority_key">Verify Intermediate Certificate Authority Key</a></h2>
|
||||||
<p><code>openssl rsa -noout -text -in <var><intermediate CA key name></var>.pem</code></p>
|
<p><code>openssl rsa -noout -text -in <var><intermediate CA key name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="create_intermediate_certificate_authority_signing_request">
|
<section id="create_intermediate_certificate_authority_signing_request">
|
||||||
<h2 id="create_intermediate_certificate_authority_signing_request"><a href="#create_intermediate_certificate_authority_signing_request">Create Intermediate Certificate Authority Signing Request</a></h2>
|
<h2><a href="#create_intermediate_certificate_authority_signing_request">Create Intermediate Certificate Authority Signing Request</a></h2>
|
||||||
<p><code>openssl req -new -sha256 -key <var><intermediate CA key name></var>.pem -out <var><intermediate CA certificate signing request name></var>.pem</code></p>
|
<p><code>openssl req -new -sha256 -key <var><intermediate CA key name></var>.pem -out <var><intermediate CA certificate signing request name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="create_intermediate_certificate_authority_certificate">
|
<section id="create_intermediate_certificate_authority_certificate">
|
||||||
<h2 id="create_intermediate_certificate_authority_certificate"><a href="#create_intermediate_certificate_authority_certificate">Create Intermediate Certificate Authority Certificate</a></h2>
|
<h2><a href="#create_intermediate_certificate_authority_certificate">Create Intermediate Certificate Authority Certificate</a></h2>
|
||||||
<p><code>openssl ca -config <var><intermediate CA configuration file></var> -extensions v3_intermediate_ca -days <var><days of validity></var> -notext -md sha256 -in <var><intermediate CA signing request name></var>.pem -out <var><intermediate CA certificate name></var>.pem</code></p>
|
<p><code>openssl ca -config <var><intermediate CA configuration file></var> -extensions v3_intermediate_ca -days <var><days of validity></var> -notext -md sha256 -in <var><intermediate CA signing request name></var>.pem -out <var><intermediate CA certificate name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="verify_intermediate_certificate_authority_certificate">
|
<section id="verify_intermediate_certificate_authority_certificate">
|
||||||
<h2 id="verify_intermediate_certificate_authority_certificate"><a href="#verify_intermediate_certificate_authority_certificate">Verify Intermediate Certificate Authority Certificate</a></h2>
|
<h2><a href="#verify_intermediate_certificate_authority_certificate">Verify Intermediate Certificate Authority Certificate</a></h2>
|
||||||
<p><code>openssl x509 -noout -text -in <var><intermediate CA certificate name></var>.pem</code></p>
|
<p><code>openssl x509 -noout -text -in <var><intermediate CA certificate name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="verify_chain_of_trust-ca_to_intermediate">
|
<section id="verify_chain_of_trust-ca_to_intermediate">
|
||||||
<h2 id="verify_chain_of_trust-ca_to_intermediate"><a href="#verify_chain_of_trust-ca_to_intermediate">Verify Chain of Trust (CA to Intermediate)</a></h2>
|
<h2><a href="#verify_chain_of_trust-ca_to_intermediate">Verify Chain of Trust (CA to Intermediate)</a></h2>
|
||||||
<p><code>openssl verify -CAfile <var><CA certificate name></var>.pem <var><intermediate CA certificate name></var>.pem</code></p>
|
<p><code>openssl verify -CAfile <var><CA certificate name></var>.pem <var><intermediate CA certificate name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="create_server_key">
|
<section id="create_server_key">
|
||||||
<h2 id="create_server_key"><a href="#create_server_key">Create Server Key</a></h2>
|
<h2><a href="#create_server_key">Create Server Key</a></h2>
|
||||||
<p><code>openssl genrsa <var><encryption type></var> -out <var><server key name></var>.pem <var><key size></var></code></p>
|
<p><code>openssl genrsa <var><encryption type></var> -out <var><server key name></var>.pem <var><key size></var></code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="verify_server_key">
|
<section id="verify_server_key">
|
||||||
<h2 id="verify_server_key"><a href="#verify_server_key">Verify Server Key</a></h2>
|
<h2><a href="#verify_server_key">Verify Server Key</a></h2>
|
||||||
<p><code>openssl rsa -noout -text -in <var><server key name></var>.pem</code></p>
|
<p><code>openssl rsa -noout -text -in <var><server key name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="create_server_certificate_signing_request">
|
<section id="create_server_certificate_signing_request">
|
||||||
<h2 id="create_server_certificate_signing_request"><a href="#create_server_certificate_signing_request">Create Server Certificate Signing Request</a></h2>
|
<h2><a href="#create_server_certificate_signing_request">Create Server Certificate Signing Request</a></h2>
|
||||||
<p><code>openssl req -new -sha256 -subj "/C=<var><country></var>/ST=<var><state/province></var>/L=<var><locality></var>/O=<var><organization></var>/CN=<var><common name></var>" -addext "subjectAltName = DNS.1:<var><alternative DNS entry></var>" -key <var><server key name></var>.pem -out <var><server certificate signing request name></var>.pem</code></p>
|
<p><code>openssl req -new -sha256 -subj "/C=<var><country></var>/ST=<var><state/province></var>/L=<var><locality></var>/O=<var><organization></var>/CN=<var><common name></var>" -addext "subjectAltName = DNS.1:<var><alternative DNS entry></var>" -key <var><server key name></var>.pem -out <var><server certificate signing request name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="create_server_certificate">
|
<section id="create_server_certificate">
|
||||||
<h2 id="create_server_certificate"><a href="#create_server_certificate">Create Server Certificate</a></h2>
|
<h2><a href="#create_server_certificate">Create Server Certificate</a></h2>
|
||||||
<p><code>openssl x509 -sha256 -req -days <var><days of validity></var> -in <var><server certificate signing request name></var>.pem -CA <var><intermediate CA certificate name></var>.pem -CAkey <var><intermediate CA key name></var>.pem -extensions SAN -extfile <(cat /etc/ssl/openssl.cnf <(printf "\n[SAN]\nsubjectAltName=DNS.1:")) -out <var><server certificate name></var>.pem</code></p>
|
<p><code>openssl x509 -sha256 -req -days <var><days of validity></var> -in <var><server certificate signing request name></var>.pem -CA <var><intermediate CA certificate name></var>.pem -CAkey <var><intermediate CA key name></var>.pem -extensions SAN -extfile <(cat /etc/ssl/openssl.cnf <(printf "\n[SAN]\nsubjectAltName=DNS.1:")) -out <var><server certificate name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="verify_server_certificate">
|
<section id="verify_server_certificate">
|
||||||
<h2 id="verify_server_certificate"><a href="#verify_server_certificate">Verify Server Certificate</a></h2>
|
<h2><a href="#verify_server_certificate">Verify Server Certificate</a></h2>
|
||||||
<p><code>openssl x509 -noout -text -in <var><server certificate name></var>.pem</code></p>
|
<p><code>openssl x509 -noout -text -in <var><server certificate name></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
<section id="verify_chain_of_trust-intermediate_to_server">
|
<section id="verify_chain_of_trust-intermediate_to_server">
|
||||||
<h2 id="verify_chain_of_trust-intermediate_to_server"><a href="#verify_chain_of_trust-intermediate_to_server">Verify Chain of Trust (Intermediate to Server)</a></h2>
|
<h2><a href="#verify_chain_of_trust-intermediate_to_server">Verify Chain of Trust (Intermediate to Server)</a></h2>
|
||||||
<p><code>openssl verify -CAfile <var><intermediate CA certificate name></var>.pem <var><server certificate></var>.pem</code></p>
|
<p><code>openssl verify -CAfile <var><intermediate CA certificate name></var>.pem <var><server certificate></var>.pem</code></p>
|
||||||
</section>
|
</section>
|
||||||
</body>
|
</body>
|
||||||
|
Loading…
x
Reference in New Issue
Block a user