Generating SSL Step 1: Verify Openssl Installed or Not
Generating SSL Step 1: Verify Openssl Installed or Not
Step 1
Verify OpenSSL installed or not
$ which openssl
Step 2
Create RSA Private Key
# The below command will create a file named 'server.pass.key' and place
it in the same folder where the command is executed. Here pass:x, x is
the password
# The below command will use the 'server.pass.key' file that just
generated and create 'server.key'.
Step 3
Create the Certificate Signing Request (CSR), utilizing the RSA private
key we generated in the last step.
# The below command will ask you for information that would be included
in the certificate. Since this is a self-signed certificate, there is no
need to provide the 'challenge password' (to leave it blank, press
enter).
You will be asked for additional details. Fill them and press enter.
Step 4
Generate a file named v3.ext with the below-listed contents:
authorityKeyIdentifier=keyid,issuer
basicConstraints=CA:FALSE
keyUsage = digitalSignature, nonRepudiation, keyEncipherment,
dataEncipherment
subjectAltName = @alt_names
[alt_names]
DNS.1 = <specify-the-same-common-name-that-you-used-while-generating-csr-in-the-last-
step>
Step 5
Create the SSL Certificate, utilizing the CSR created in the last step.
$ openssl x509 -req -sha256 -extfile v3.ext -days 365 -in server.csr
-signkey server.key -out server.crt
Signature ok
subject=/C=<country>/ST=<state>/L=<locality>/O=<org
anization-name>/OU=<organization-unit-name>/CN=<common-name-
probably-server-fqdn>/emailAddress=<email-address-provided-while-
generating-csr>
Getting Private key
$
If you have not ext file then five the following command to generate SSL
Certificate
$ openssl x509 -req -sha256 -days 365 -in server.csr -signkey server.key
-out server.crt
Step 6
Creating P12
$ openssl pkcs12 -export -name servercert -in server.crt -inkey
server.key -out myp12keystore.p12
In windows, first you have to download the openssl from the official site and
extract that zip file and set the path on cmd run as admin mode
set OPENSSL_CONF=path of the open SSL\openssl-0.9.8k_X64\openssl.cnf