Difference between revisions of "Generating SSL Server Certificate"

From Dogtag
Jump to: navigation, search
m (Generating CSR)
m (Issuing Certificate)
 
Line 32: Line 32:
 
* [[Issuing SSL Server Certificate with CMC]]
 
* [[Issuing SSL Server Certificate with CMC]]
 
* [[Issuing SSL Server Certificate with OpenSSL]]
 
* [[Issuing SSL Server Certificate with OpenSSL]]
 +
* [[Issuing SSL Server Certificate with PKI CLI]]
 
* [[Certificate Enrollment with PKI CLI]]
 
* [[Certificate Enrollment with PKI CLI]]
  

Latest revision as of 23:36, 24 June 2020

Properties

  • Subject DN: cn=server.example.com,ou=pki-tomcat,o=EXAMPLE
  • Key:
    • type: rsa
    • algorithm: SHA256withRSA
    • size: 2048
  • Basic constraints: None
  • Key usage extension (critical):
    • Digital Signature
    • Non Repudiation
    • Key Encipherment
    • Data Encipherment
  • Extended key usage extension:
    • TLS Web Server Authentication

Self-Signed Certificate

Generating CSR

Issuing Certificate

References