关于利用openssl生成证书的问题(请求版主相助!)
1.生成跟证书(CA):
[root@airwayORA misc]# ./CA.sh -newca
故建立好了CA服务器,根证书的私钥为:/usr/local/openssl/ssl/misc/demoCA/private//usr/local/openssl/ssl/misc/demoCA/private/cakey.pem,
根证书为:/usr/local/openssl/ssl/misc/demoCA/careq.pem
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
2.签署服务器证书:
@生成服务器私钥:
[root@airwayORA misc]# openssl genrsa -des3 -out server.key 1024
故生成服务器私钥为:/usr/local/openssl/ssl/misc/server.key
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[root@airwayORA misc]# openssl req -new -key server.key -out server.csr
生成服务器证书为:/usr/local/openssl/ssl/misc/server.csr
最后把server.crt文件mv成newreq.pem,然后用CA.sh来签证就可以了
[root@airwayORA misc]# ls
CA.pl CA.sh c_hash c_info c_issuer c_name demoCA server.csr server.key
[root@airwayORA misc]# mv server.csr newreq.pem
[root@airwayORA misc]# ls
CA.pl CA.sh c_hash c_info c_issuer c_name demoCA newreq.pem server.key
[root@win ssl.crt]# mv server.csr newreq.pem
[root@airwayORA misc]# ./CA.sh -sign
Using configuration from /usr/share/ssl/openssl.cnf
Enter pass phrase for ./demoCA/private/cakey.pem:
unable to load CA private key
30442:error:06065064:digital envelope routines:EVP_DecryptFinal:bad decrypt:evp_enc.c:438:
30442:error:0906A065EM routinesEM_do_header:bad decrypt:pem_lib.c:421:
cat: newcert.pem: No such file or directory
Signed certificate is in newcert.pem
各位高手看看蓝色部分出现的情况是什么引起的,谢谢!