Skip to content

Identity CA operations

Create an identity certificate

Create the request

openssl req -new \
    -config etc/csr/identity.conf \
    -out certs/alice-id.csr \
    -keyout certs/alice-id.key

Create the identity certificate

openssl ca \
    -config etc/ca/identity-ca.conf \
    -in certs/alice-id.csr \
    -out certs/alice-id.crt \
    -extensions identity_ext

Create a PKCS#12

openssl pkcs12 -export \
    -name "Alice Baumann (Zava)" \
    -caname "ZAVA IDENTITY CA 01" \
    -caname "ZAVA ROOT CA 01" \
    -inkey certs/alice-id.key \
    -in certs/alice-id.crt \
    -certfile ca/identity-ca01/identity-ca01-chain.pem \
    -out certs/alice-id.p12

Check PKCS#12

openssl pkcs12 -info -in certs/alice-id.p12

Create an encryption certificate

Create the request

openssl req -new \
    -config etc/csr/encryption.conf \
    -out certs/alice-enc.csr \
    -keyout certs/alice-enc.key

Create the encryption certificate

openssl ca \
    -config etc/ca/identity-ca.conf \
    -in certs/alice-enc.csr \
    -out certs/alice-enc.crt \
    -extensions encryption_ext

Create a PKCS#12

openssl pkcs12 -export \
    -name "Alice Baumann (Zava)" \
    -caname "ZAVA IDENTITY CA 01" \
    -caname "ZAVA ROOT CA 01" \
    -inkey certs/alice-enc.key \
    -in certs/alice-enc.crt \
    -certfile ca/identity-ca01/identity-ca01-chain.pem \
    -out certs/alice-enc.p12

Check PKCS#12

openssl pkcs12 -info -in certs/alice-enc.p12

Revoke a certificate

openssl ca \
    -config etc/ca/identity-ca.conf \
    -revoke ca/identity-ca01/archives/02.pem \
    -crl_reason keyCompromise

OpenSSL CA Parameters

Generate the CRL

openssl ca -gencrl \
    -config etc/ca/identity-ca.conf \
    -out crl/identity-ca01.crl

Check the CRL

openssl crl -in crl/identity-ca01.crl -text