Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Gerar Chave Privada com Password (-des3) 4096 Bits
- openssl genrsa -des3 -out rootCA.key 4096
- # Gerar CA
- openssl req -x509 -new -nodes -key rootCA.key -sha256 -days 730 -out rootCA.pem
- # Gerar Chave Privada para Dispositivo
- openssl genrsa -des3 -out device.key 4096
- # Gerar CSR
- openssl req -new -key device.key -out device.csr
- # Gerar CRT
- openssl x509 -req -in device.csr -CA rootCA.pem -CAkey rootCA.key -CAcreateserial -out device.crt -days 730 -sha256
- # Exportar para P12
- openssl pkcs12 -export -out device.p12 -inkey device.key -in device.crt -certfile rootCA.pem
- # Exportar para P12 sem RC2 (Compativel com o Munin) [Adicionar -descert]
- openssl pkcs12 -export -out device.p12 -inkey device.key -in device.crt -certfile rootCA.pem -descert
- # Ler P12
- openssl pkcs12 -info -in device.pfx
- # Ler CSR
- openssl req -text -noout -verify -in domain.csr
- # Ler CRT
- openssl x509 -text -noout -in domain.crt
- # Verificar se o Certificado foi assinado pela CA
- openssl verify -verbose -CAfile ca.pem domain.crt
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement