284354749 发表于 2018-8-30 07:26:01

shell完成自动部署CA自签服务器搭建

#!/bin/bash  
# Function: This script is made for auto create ca .
  
# made by : zhiwang.wang
  
# contact: jishuweiwang.blog.51cto.com
  

  
#create server-point private key
  
openssl genrsa 2048 > server.key ; chmod 600 server.key
  
# anther command: (umask 077; openssl genrsa -out server2.key 1024)
  

  
# produce public key from server-point private key
  
openssl rsa -in server.key -pubout > public.key
  

  
# produce self-signed certificate from server-point private key
  
echo "CN
  
BJ
  
BJ
  
DreamGame
  
Tech
  
ca.dreamingame.com
  
caadmin"|openssl req -new -x509 -key server.key -out server.crt -days 365
  

  
# modify openssl config file , it only effect when use for CA.
  
cd /etc/pki/tls/
  
sed -i '/countryName_default/s#XX#CN#g' openssl.cnf
  
sed -i 's#Default City#BJ#g' openssl.cnf
  
sed -i 's#Default Company Ltd#DreamGame#g' openssl.cnf
  
sed -i '/ProvinceName_default/c\stateOrProvinceName_default   = BJ' openssl.cnf
  
sed -i '/UnitName_default/c\organizationalUnitName_default= Tech' openssl.cnf
  

  
cd /etc/pki/CA/
  
(umask 077; openssl genrsa -out private/cakey.pem 2048)
  

  
echo "
  

  

  

  

  
ca.dreamingame.com
  
caadmin
  
" |openssl req -new -x509 -key private/cakey.pem -out cacert.pem
  

  
touch index.txt serial
  
echo 01 > serial
  

  
# End


页: [1]
查看完整版本: shell完成自动部署CA自签服务器搭建