Component CA operations
Create a simple SSL certificate
Create the request
openssl req -new \
-config etc/csr/server.conf \
-out certs/simple-server.csr \
-keyout certs/simple-server.key
Create the certificate
openssl ca \
-config etc/ca/component-ca.conf \
-in certs/simple-server.csr \
-out certs/simple-server.crt \
-extensions server_ext
Create a SSL certificate with SubjectAlternativeNames
Create the request
openssl req -new \
-config etc/csr/serverSAN.conf \
-out certs/san-server.csr \
-keyout certs/san-server.key
Create the certificate
openssl ca \
-config etc/ca/component-ca.conf \
-in certs/san-server.csr \
-out certs/san-server.crt \
-extensions server_ext
Create a SSL client certificate
Create the request
openssl req -new \
-config etc/csr/client.conf \
-out certs/client.csr \
-keyout certs/client.key
Create the certificate
openssl ca \
-config etc/ca/component-ca.conf \
-in certs/client.csr \
-out certs/client.crt \
-extensions client_ext
Create a time-stamping certificate
Create the request
openssl req -new \
-config etc/csr/timestamp.conf \
-out certs/tsa.csr \
-keyout certs/tsa.key
Create the certificate
openssl ca \
-config etc/ca/component-ca.conf \
-in certs/tsa.csr \
-out certs/tsa.crt \
-extensions timestamp_ext
Create an OCSP certificate
Create the request
openssl req -new \
-config etc/csr/ocspsign.conf \
-out certs/ocsp2.csr \
-keyout certs/ocsp2.key
Create the certificate
openssl ca \
-config etc/ca/component-ca.conf \
-in certs/ocsp.csr \
-out certs/ocsp.crt \
-extensions ocspsign_ext
Revoke a certificate
openssl ca \
-config etc/ca/component-ca.conf \
-revoke ca/component-ca01/archives/01.pem \
-crl_reason superseded
OpenSSL CA Parameters
Generate the CRL
openssl ca -gencrl \
-config etc/ca/component-ca.conf \
-out crl/component-ca01.crl
Check the CRL
openssl crl -in crl/component-ca01.crl -text