CA重要配置文件:
/etc/pki/tls/openssl.cnf

1.生成私钥
1.1不加密
:(umask 066;openssl genrsa -out private.key 1024)
:(umask 066;openssl genrsa -out /etc/pki/CA/private/cakey.pem 1024)

1.2加密
:(umask 066;openssl genrsa -out private.key -des 1024)
:(umask 066;openssl genrsa -out /etc/pki/CA/private/cakey .pem -des 1024)

1.2.1解密
:openssl rsa -in private.key -out private.key2

2.根据私钥生成公钥
2.1由没有加密的私钥(private.key2)生成公钥(public.key2)
openssl rsa -in private.key2 -pubout -out public.key2

2.2由有加密的私钥(private.key)生成公钥(public.key)
openssl rsa -in private.key -pubout -out public.key

3.生成的公钥与私钥

posted on
2018-09-17 11:12
圆缘
阅读(
17652)
评论()
收藏
举报