Collections:
Other Resources:
OpenSSL "x509 -req" - Quick Way to Sign CSR
How to sign a CSR with OpenSSL "x509" command? I want a quick way to sign a CSR without setting the OpenSSL "ca" command.
✍: FYIcenter.com
Normally, you should set up OpenSSL "ca" command to sign a CSR.
But if you want quick alternative, you can use the "x509" command to sign a CSR
as shown in the test below:
C:\Users\fyicenter>\local\OpenSSL\openssl
OpenSSL> req -in my_rsa.csr -subject -noout
subject=/C=us/ST=NY/L=New York/O=Donald Inc./OU=IT/CN=www.donald.inc/emailAddres
s=john@donald.inc
OpenSSL> req -in my_rsa.csr -verify -noout
verify OK
OpenSSL> x509 -req -in my_rsa.csr -CA my_ca.crt -CAkey my_ca.key -out my_rsa.crt
-set_serial 2000
Signature ok
subject=/C=us/ST=NY/L=New York/O=Donald Inc./OU=IT/CN=www.donald.inc/emailAddres
s=john@donald.inc
Getting CA Private Key
Enter pass phrase for my_ca.key:fyicenter
OpenSSL> x509 -in my_rsa.crt -subject -noout
subject= /C=us/ST=NY/L=New York/O=Donald Inc./OU=IT/CN=www.donald.inc
/emailAddress=john@donald.inc
OpenSSL> x509 -in my_rsa.crt -issuer -noout
issuer= /C=US/ST=TX/L=City/O=FYIcenter.com/OU=Security/CN=FYIcenter Root CA
/emailAddress=root-ca@fyicenter.com
Notes about the test:
⇒ OpenSSL "x509 -req" - Error "my_ca.srl: No error"
2018-02-01, ∼3172🔥, 0💬
Popular Posts:
Certificate summary - Owner: *.wordpress.org, Domain Control Validated, *.wordpress.org Issuer: SERI...
Certificate summary - Owner: *.soundcloud.com, Domain Control Validated, GB Issuer: GlobalSign Domai...
Certificate summary - Owner: *.yelp.com, Domain Control Validated, *.yelp.com Issuer: SERIALNUMBER=0...
Certificate Summary: Subject: www.tistory.com Issuer: Symantec Class 3 EV SSL CA - G3 Expiration: 20...
Certificate Summary: Subject: DigiCert SHA2 High Assurance Server CA Issuer: DigiCert High Assurance...