User Tools

Site Tools


certificates:certificates_guide

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
certificates:certificates_guide [2024/01/02 16:47] – [SSL Info] bstaffordcertificates:certificates_guide [2025/07/10 19:00] (current) – [Strip Password from Base64] bstafford
Line 4: Line 4:
  
 Extra info can also be found on [[http://www.sslshopper.com/article-most-common-openssl-commands.html|Certificates]] and [[https://www.sslshopper.com/article-most-common-java-keytool-keystore-commands.html|Keystores]] and [[https://www.sslshopper.com/ssl-converter.html|Converting]]. Extra info can also be found on [[http://www.sslshopper.com/article-most-common-openssl-commands.html|Certificates]] and [[https://www.sslshopper.com/article-most-common-java-keytool-keystore-commands.html|Keystores]] and [[https://www.sslshopper.com/ssl-converter.html|Converting]].
 +=====Strip Password from Base64=====
 +Strip a password from a Base64 file that has both certificate and key.
 +<code>openssl rsa -in [file1.key] -out [file2.key]</code>
 =====Add Password to Base64===== =====Add Password to Base64=====
 Add a password to a Base64 file that is not Add a password to a Base64 file that is not
Line 11: Line 14:
 <code>sudo cat /etc/nginx/certs/intermediate.pem >> /etc/nginx/certs/certfile.pem</code> <code>sudo cat /etc/nginx/certs/intermediate.pem >> /etc/nginx/certs/certfile.pem</code>
 <code>sudo systemctl restart nginx</code> <code>sudo systemctl restart nginx</code>
-=====Strip Password from Base64===== +
-Strip a password from a Base64 file that has both certificate and key. +
-<code>openssl rsa -in [file1.key] -out [file2.key]</code>+
 ===== Create Root CA and Web Cert ===== ===== Create Root CA and Web Cert =====
 Generate Private Key:  Generate Private Key: 
Line 28: Line 29:
  
 CAs should include a Subject Key Identifier in all CA certificates. CAs should include a Subject Key Identifier in all CA certificates.
 +
 +Create web Certificate Signing Request AND new key
 +<code>openssl req -newkey rsa:2048 -keyout webserver.key -out webserver.csr</code>
  
  
certificates/certificates_guide.1704214039.txt.gz · Last modified: by bstafford