Identity CA operations
Create an identity certificate
Create the request
openssl req -new \
-config etc/csr/identity.conf \
-out certs/alice-id.csr \
-keyout certs/alice-id.key
Create the identity certificate
openssl ca \
-config etc/ca/identity-ca.conf \
-in certs/alice-id.csr \
-out certs/alice-id.crt \
-extensions identity_ext
Create a PKCS#12
openssl pkcs12 -export \
-name "Alice Baumann (Zava)" \
-caname "ZAVA IDENTITY CA 01" \
-caname "ZAVA ROOT CA 01" \
-inkey certs/alice-id.key \
-in certs/alice-id.crt \
-certfile ca/identity-ca01/identity-ca01-chain.pem \
-out certs/alice-id.p12
Check PKCS#12
openssl pkcs12 -info -in certs/alice-id.p12
Create an encryption certificate
Create the request
openssl req -new \
-config etc/csr/encryption.conf \
-out certs/alice-enc.csr \
-keyout certs/alice-enc.key
Create the encryption certificate
openssl ca \
-config etc/ca/identity-ca.conf \
-in certs/alice-enc.csr \
-out certs/alice-enc.crt \
-extensions encryption_ext
Create a PKCS#12
openssl pkcs12 -export \
-name "Alice Baumann (Zava)" \
-caname "ZAVA IDENTITY CA 01" \
-caname "ZAVA ROOT CA 01" \
-inkey certs/alice-enc.key \
-in certs/alice-enc.crt \
-certfile ca/identity-ca01/identity-ca01-chain.pem \
-out certs/alice-enc.p12
Check PKCS#12
openssl pkcs12 -info -in certs/alice-enc.p12
Revoke a certificate
openssl ca \
-config etc/ca/identity-ca.conf \
-revoke ca/identity-ca01/archives/02.pem \
-crl_reason keyCompromise
OpenSSL CA Parameters
Generate the CRL
openssl ca -gencrl \
-config etc/ca/identity-ca.conf \
-out crl/identity-ca01.crl
Check the CRL
openssl crl -in crl/identity-ca01.crl -text