baumi's blog

baumi's personal blog … Linux, OS X, Windows, Random things, …

SSL Zertifikate: CSR für Apache/Mod_SSL erzeugen …

#private key erstellen:
openssl genrsa -out www.demo.com.key 2048

#CSR (Zertifikatsrequest) erstellen:
#common name = domain name, zB www.test.com
openssl req -new -key www.demo.com.key -out www.demo.com.csr

Beispiele zu den jeweiligen abgefragten Attributen:

   Country Name (2 letter code) [AU]: DE
   State or Province Name (full name) [Some-State]: Bayern
   Locality Name (eg, city) []: Ingolstadt
   Organization Name (eg, company) [Internet Widgits Pty Ltd]: Unternehmen GmbH
   Organizational Unit Name (eg, section) []:
   Common Name (eg, YOUR name) []: www.domain.de
   Email Address []: admin@domain.de

#CSR anzeigen
cat www.demo.com.csr

Mit dem CSR das Zertifikat kaufen (www.interssl.com z.B.)

Apache config:

<VirtualHost 46.4.8.147:443>

DocumentRoot /home/frank/www/www.demo.com

ServerName www.demo.com

ServerAlias demo.com

SSLEngine on

SSLCertificateFile /home/frank/ssl/www.demo.com.crt

SSLCertificateKeyFile /home/frank/ssl/www.demo.com.key

SSLCertificateChainFile /home/frank/ssl/RapidSSL_CA_bundle.pem

.
.
.
https://knowledge.rapidssl.com/library/VERISIGN/ALL_OTHER/RapidSSL%20Intermediate/RapidSSL_CA_bundle.pem

Comments are currently closed.