Skip to content

Root CA

Create directories

mkdir -p ca/root-ca01/private ca/root-ca01/db ca/root-ca01/archives crl certs
chmod 700 ca/root-ca01/private

Create databases

touch ca/root-ca01/db/root-ca01.db
touch ca/root-ca01/db/root-ca01.db.attr
echo 01 > ca/root-ca01/db/root-ca01.crt.srl
echo 01 > ca/root-ca01/db/root-ca01.crl.srl

Create the request

openssl req -new \
    -config etc/ca/root-ca.conf \
    -out ca/root-ca01/root-ca01.csr \
    -keyout ca/root-ca01/private/root-ca01.key

Check the request

openssl req -in ca/root-ca01/root-ca01.csr -text

Create the root CA certificate

openssl ca -selfsign \
    -config etc/ca/root-ca.conf \
    -in ca/root-ca01/root-ca01.csr \
    -out ca/root-ca01/root-ca01.crt \
    -extensions root_ca_ext 

Check the root CA certificate

openssl x509 -in ca/root-ca01/root-ca01.crt -text -noout

Create the initial CRL

openssl ca -gencrl \
    -config etc/ca/root-ca.conf \
    -out crl/root-ca01.crl

Check the CRL

openssl crl -in crl/root-ca01.crl -text