Skip to content

Component CA operations

Create a simple SSL certificate

Create the request

openssl req -new \
    -config etc/csr/server.conf \
    -out certs/simple-server.csr \
    -keyout certs/simple-server.key

Create the certificate

openssl ca \
    -config etc/ca/component-ca.conf \
    -in certs/simple-server.csr \
    -out certs/simple-server.crt \
    -extensions server_ext

Create a SSL certificate with SubjectAlternativeNames

Create the request

openssl req -new \
    -config etc/csr/serverSAN.conf \
    -out certs/san-server.csr \
    -keyout certs/san-server.key

Create the certificate

openssl ca \
    -config etc/ca/component-ca.conf \
    -in certs/san-server.csr \
    -out certs/san-server.crt \
    -extensions server_ext

Create a SSL client certificate

Create the request

openssl req -new \
    -config etc/csr/client.conf \
    -out certs/client.csr \
    -keyout certs/client.key

Create the certificate

openssl ca \
    -config etc/ca/component-ca.conf \
    -in certs/client.csr \
    -out certs/client.crt \
    -extensions client_ext

Create a time-stamping certificate

Create the request

openssl req -new \
    -config etc/csr/timestamp.conf \
    -out certs/tsa.csr \
    -keyout certs/tsa.key

Create the certificate

openssl ca \
    -config etc/ca/component-ca.conf \
    -in certs/tsa.csr \
    -out certs/tsa.crt \
    -extensions timestamp_ext

Create an OCSP certificate

Create the request

openssl req -new \
    -config etc/csr/ocspsign.conf \
    -out certs/ocsp2.csr \
    -keyout certs/ocsp2.key

Create the certificate

openssl ca \
    -config etc/ca/component-ca.conf \
    -in certs/ocsp.csr \
    -out certs/ocsp.crt \
    -extensions ocspsign_ext

Revoke a certificate

openssl ca \
    -config etc/ca/component-ca.conf \
    -revoke ca/component-ca01/archives/01.pem \
    -crl_reason superseded

OpenSSL CA Parameters

Generate the CRL

openssl ca -gencrl \
    -config etc/ca/component-ca.conf \
    -out crl/component-ca01.crl

Check the CRL

openssl crl -in crl/component-ca01.crl -text