Up to higher level directory | |||
Name | Date | Size | |
---|---|---|---|
badclient.key | 22-Oct-2020 | 916 | |
badclient.pem | 22-Oct-2020 | 973 | |
badserver.key | 22-Oct-2020 | 916 | |
badserver.pem | 22-Oct-2020 | 973 | |
BUILD | 22-Oct-2020 | 886 | |
ca-openssl.cnf | 22-Oct-2020 | 541 | |
ca.key | 22-Oct-2020 | 912 | |
ca.pem | 22-Oct-2020 | 855 | |
client.key | 22-Oct-2020 | 920 | |
client.pem | 22-Oct-2020 | 798 | |
README | 22-Oct-2020 | 2K | |
server0.key | 22-Oct-2020 | 916 | |
server0.pem | 22-Oct-2020 | 794 | |
server1-openssl.cnf | 22-Oct-2020 | 790 | |
server1.key | 22-Oct-2020 | 912 | |
server1.pem | 22-Oct-2020 | 964 |
1 The test credentials (CONFIRMEDTESTKEY) have been generated with the following 2 commands: 3 4 Bad credentials (badclient.* / badserver.*): 5 ============================================ 6 7 These are self-signed certificates: 8 9 $ openssl req -x509 -newkey rsa:1024 -keyout badserver.key -out badserver.pem \ 10 -days 3650 -nodes 11 12 When prompted for certificate information, everything is default except the 13 common name which is set to badserver.test.google.com. 14 15 16 Valid test credentials: 17 ======================= 18 19 The ca is self-signed: 20 ---------------------- 21 22 $ openssl req -x509 -new -newkey rsa:1024 -nodes -out ca.pem -config ca-openssl.cnf -days 3650 -extensions v3_req 23 When prompted for certificate information, everything is default. 24 25 client is issued by CA: 26 ----------------------- 27 28 $ openssl genrsa -out client.key.rsa 1024 29 $ openssl pkcs8 -topk8 -in client.key.rsa -out client.key -nocrypt 30 $ rm client.key.rsa 31 $ openssl req -new -key client.key -out client.csr 32 33 When prompted for certificate information, everything is default except the 34 common name which is set to testclient. 35 36 $ openssl ca -in client.csr -out client.pem 37 38 server0 is issued by CA: 39 ------------------------ 40 41 $ openssl genrsa -out server0.key.rsa 1024 42 $ openssl pkcs8 -topk8 -in server0.key.rsa -out server0.key -nocrypt 43 $ rm server0.key.rsa 44 $ openssl req -new -key server0.key -out server0.csr 45 46 When prompted for certificate information, everything is default except the 47 common name which is set to *.test.google.com.au. 48 49 $ openssl ca -in server0.csr -out server0.pem 50 51 server1 is issued by CA with a special config for subject alternative names: 52 ---------------------------------------------------------------------------- 53 54 $ openssl genrsa -out server1.key.rsa 1024 55 $ openssl pkcs8 -topk8 -in server1.key.rsa -out server1.key -nocrypt 56 $ rm server1.key.rsa 57 $ openssl req -new -key server1.key -out server1.csr -config server1-openssl.cnf 58 59 When prompted for certificate information, everything is default except the 60 common name which is set to *.test.google.com. 61 62 $ openssl ca -in server1.csr -out server1.pem 63