software:openssl:createconfig
Differences
This shows you the differences between two versions of the page.
| software:openssl:createconfig [2025/10/22 01:36] – created rodolico | software:openssl:createconfig [2025/10/23 18:40] (current) – rodolico | ||
|---|---|---|---|
| Line 3: | Line 3: | ||
| While not actually required, it cuts down on the number of things you have to type. Creating this file allows you to use the -config parameter on many commands, with values drawn from here. | While not actually required, it cuts down on the number of things you have to type. Creating this file allows you to use the -config parameter on many commands, with values drawn from here. | ||
| - | For example, everything in the **[ req_distinguished_name ]** is asked for every time you create a certificate, | + | For example, everything in the **[ req_distinguished_name ]** is asked for every time you create a certificate, |
| This file is designed to be used several places, from creating the initial CA to creating a CSR, to creating the final Server Cert, so it is more complex than it needs to be. | This file is designed to be used several places, from creating the initial CA to creating a CSR, to creating the final Server Cert, so it is more complex than it needs to be. | ||
| Line 21: | Line 21: | ||
| distinguished_name | distinguished_name | ||
| prompt | prompt | ||
| - | # | ||
| req_extensions | req_extensions | ||
| Line 31: | Line 30: | ||
| O = Example Corp | O = Example Corp | ||
| OU = Office | OU = Office | ||
| + | # CN should be different for all certs | ||
| CN = example.org | CN = example.org | ||
| emailAddress = admin@example.org | emailAddress = admin@example.org | ||
| Line 48: | Line 48: | ||
| default_ca = CA_default | default_ca = CA_default | ||
| + | # This is used when we create a CA | ||
| [ CA_default ] | [ CA_default ] | ||
| - | keyUsage = critical, digitalSignature, | + | keyUsage = critical, digitalSignature, |
| + | extendedKeyUsage = serverAuth, clientAuth | ||
| basicConstraints = CA:TRUE | basicConstraints = CA:TRUE | ||
software/openssl/createconfig.txt · Last modified: 2025/10/23 18:40 by rodolico
