mkdir cert_v3 cd cert_v3
mkdir ca cd ca
[ req ] distinguished_name = req_distinguished_name prompt = no [ req_distinguished_name ] O = MEF [ v3_ca ] subjectKeyIdentifier = hash authorityKeyIdentifier = keyid:always,issuer basicConstraints = critical, CA:true keyUsage = critical, digitalSignature, cRLSign, keyCertSign
openssl genrsa -aes256 -out ca.key 4096
请合理设置密码强度,长度至少为8个字符,且包含数字、大写字母、小写字母、特殊符号中的两种及以上字符组合。
openssl req -out ca.csr -key ca.key -new -config ./ca_cert.conf
openssl x509 -req -in ca.csr -out ca.crt -sha256 -days 1000 -extfile ./ca_cert.conf -extensions v3_ca -signkey ca.key