Ubuntu - Generating daim ntawv pov thawj kos npe thov (CSR)

Ntaub ntawv

Tsim Tsab Ntawv Thov Daim Ntawv Pom Zoo (CSR)

Los ua kom tiav Daim Ntawv Pov Thawj Kos Npe (CSR), koj yuav tsum tsim koj tus kheej qhov tseem ceeb. Koj tuaj yeem khiav cov lus txib nram qab no los ntawm lub sijhawm kom dav hlau los tsim qhov tseem ceeb:

openssl genrsa -des3 -out server.key 1024
Generating RSA private key, 1024 ntsis ntev modulus ..................... ++++++ .............. ... ++++++ sau tsis tau 'random state' e yog 65537 (0x10001) Sau kab lus rau server.key:

Koj tau tam sim no nkag mus rau koj cov passphrase. Rau kev ruaj ntseg zoo, nws yuav tsum muaj tsawg kawg yog yim cim. Qhov tsawg kawg yog ntev thaum specifying -des3 yog plaub cim. Nws yuav tsum muaj cov zauv thiab / lossis cov cim sau ntawv thiab tsis yog lo lus nyob rau hauv ib phau ntawv txhais lus. Kuj tseem nco ntsoov tias koj cov ntawv tuaj yeem yog qhov xwm txheej.

Re-type lub passphrase kom paub tseeb. Thaum koj tau rov ntaus nws kom raug, tus yuam sij neeg yog tsim thiab muab cia rau hauv file server .


[Ceeb toom]

Koj tuaj yeem khiav koj lub vas sab web ruaj ntseg yam tsis muaj ib daim ntawv xaiv tsa. Qhov no yog qhov yooj yim vim tias koj yuav tsis tau nkag mus rau passphrase txhua zaus koj pib koj qhov web server zoo. Tab sis nws yog insecure heev thiab ib qho nyuaj ntawm lub ntsiab txhais tau hais tias ib tug compromise ntawm tus neeg rau zaub mov thiab.

Nyob rau hauv txhua qhov teeb meem, koj tuaj yeem xaiv khiav koj tus neeg saib xyuas kev ruaj ntseg hauv lub web tsis muaj ib daim ntawv xaiv tsa uas tawm ntawm qhov hloov mus-hloov tawm ntawm lub caij ntuj tshiab los yog muab cov lus txib nram qab no rau ntawm qhov chaw nres tsheb:

openssl rsa -in server.key-tawm server.key.insecure

Thaum koj khiav qhov hais kom ua saum toj no, tus yuam sij tseem ceeb yuav muab cia rau hauv cov ntaub ntawv server.key.insecure . Koj siv tau cov ntaub ntawv no los tsim cov CSR uas tsis muaj cov passphrase.

Los tsim cov CSR, khiav cov lus txib nram qab no ntawm qhov chaw dav hlau kom sai:

openssl req -new -key server.key -out server.csr

Nws yuav qhia koj kom nkag siab txog cov ntawv yuam kev. Yog tias koj nkag mus rau qhov kev cai hla tuaj yeem , nws yuav qhia rau koj kom nkag mus rau Lub Chaw Npe, Qhov Chaw Npe, Email Nqi, thiab lwm yam. Thaum koj sau tag nrho cov ntsiab lus no, koj tus CSR yuav raug tsim thiab nws yuav muab khaws cia rau hauv cov ntaub ntawv server.csr . Koj tuaj yeem xa daim ntawv CSR mus rau CA kom ua tiav. Lub CAJ yuav siv cov ntaub ntawv no CSR thiab muab daim ntawv pov thawj. Ntawm qhov tod tes, koj tuaj yeem tsim daim ntawv pov thawj nrog tus kheej kos npe siv tus CSR no.

* Ubuntu Cov Ntawv Cob Qhia Ntawv Qhia