Jul. 18th, 2017
X.509 сертификат с subjectAltName
Jul. 18th, 2017 08:44 amДля создания сабжа, без которого Google Chrome смотрит на сайты как на говно, надо:
1. Certificate request. В openssl.conf
2. CA при подписании
./openssl.conf
Certificate request с subjectAltName:
1. Certificate request. В openssl.conf
[req] req_extensions = v3_req [v3_req] subjectAltName = @alt_names [alt_names] DNS.1 = name1.example DNS.2 = name2.example IP.1 = 10.1.1.1
2. CA при подписании
[ CA_default ] copy_extensions = copy
Самоподписанный сертификат с subjectAltName:
openssl req -new -x509 -nodes -keyout test.key -config ./openssl.conf -days 3650 -out test.crt
./openssl.conf
[req] default_bits = 2048 default_md = sha256 x509_extensions = v3_req distinguished_name = req_distinguished_name [v3_req] subjectAltName = @alt_names [alt_names] DNS.1 = name1.example DNS.2 = name2.example [req_distinguished_name] commonName = Common Name (e.g. server FQDN or YOUR name) commonName_max = 64 commonName_default = name1.example