Root CA
Create directories
mkdir -p ca/root-ca01/private ca/root-ca01/db ca/root-ca01/archives crl certs
chmod 700 ca/root-ca01/private
Create databases
touch ca/root-ca01/db/root-ca01.db
touch ca/root-ca01/db/root-ca01.db.attr
echo 01 > ca/root-ca01/db/root-ca01.crt.srl
echo 01 > ca/root-ca01/db/root-ca01.crl.srl
Create the request
openssl req -new \
-config etc/ca/root-ca.conf \
-out ca/root-ca01/root-ca01.csr \
-keyout ca/root-ca01/private/root-ca01.key
Check the request
openssl req -in ca/root-ca01/root-ca01.csr -text
Create the root CA certificate
openssl ca -selfsign \
-config etc/ca/root-ca.conf \
-in ca/root-ca01/root-ca01.csr \
-out ca/root-ca01/root-ca01.crt \
-extensions root_ca_ext
Check the root CA certificate
openssl x509 -in ca/root-ca01/root-ca01.crt -text -noout
Create the initial CRL
openssl ca -gencrl \
-config etc/ca/root-ca.conf \
-out crl/root-ca01.crl
Check the CRL
openssl crl -in crl/root-ca01.crl -text