Skip to content

Identity CA

Create directories

mkdir -p ca/identity-ca01/private ca/identity-ca01/db  ca/identity-ca01/archives crl certs
chmod 700 ca/identity-ca01/private

Create databases

touch ca/identity-ca01/db/identity-ca01.db
touch ca/identity-ca01/db/identity-ca01.db.attr
echo 01 > ca/identity-ca01/db/identity-ca01.crt.srl
echo 01 > ca/identity-ca01/db/identity-ca01.crl.srl

Create the request

openssl req -new \
    -config etc/ca/identity-ca.conf \
    -out ca/identity-ca01/identity-ca01.csr \
    -keyout ca/identity-ca01/private/identity-ca01.key

Check the request

openssl req -in ca/identity-ca01/identity-ca01.csr -text

Create the identity CA certificate

openssl ca \
    -config etc/ca/root-ca.conf \
    -in ca/identity-ca01/identity-ca01.csr \
    -out ca/identity-ca01/identity-ca01.crt \
    -extensions intermediate_ca_ext

Check the certificate

openssl x509 -in ca/identity-ca01/identity-ca01.crt -text -noout

Create the initial CRL

openssl ca -gencrl \
    -config etc/ca/identity-ca.conf \
    -out crl/identity-ca01.crl

Create the PEM Bundle

cat ca/identity-ca01/identity-ca01.crt \
    ca/root-ca01/root-ca01.crt > \
    ca/identity-ca01/identity-ca01-chain.pem