Collections:
Other Resources:
OpenSSL "x509 -req" - Error "my_ca.srl: No error"
Why I am getting the "my_ca.srl: No error" error when trying to sign a CSR with OpenSSL "x509" command?
✍: FYIcenter.com
You are getting the "my_ca.srl: No error" error when using OpenSSL "x509" command
to sign a CSR, because OpenSSL is not able to access the default serial number file:
my_ca.srl.
When using "x509" command to sign CSR, you have to use the following options to help OpenSSL to manage how serial number should be provided to the new certificates.
The test shows you how to create a default serial number file:
C:\Users\fyicenter>copy CON my_ca.srl
1000
<Ctrl-Z>
C:\Users\fyicenter>copy CON my_ca.srl
613 my_ca.crl
1,094 my_ca.crt
1,041 my_ca.key
C:\Users\fyicenter>\local\OpenSSL\openssl
OpenSSL> x509 -req -in my_rsa.csr -CA my_ca.crt -CAkey my_ca.key -out my_rsa.crt
Signature ok
subject=/C=us/ST=NY/L=New York/O=Donald Inc./OU=IT/CN=www.donald.inc/emailAddres
s=john@donald.inc
Getting CA Private Key
Enter pass phrase for my_ca.key:
OpenSSL> x509 -in my_rsa.crt -serial -noout
serial=1001
⇒ OpenSSL "x509 -pubkey" - Export Public Key"
2018-02-08, ≈15🔥, 0💬
Popular Posts:
Certificate Summary: Subject: DO_NOT_TRUST_FiddlerRoot Issuer: DO_NOT_TRUST_FiddlerRoot Expiration: ...
Certificate summary - Owner: sberbank.ru, DSIT, Sberbank of Russia, L=Moscow, ST=Russian Federation,...
Certificate Summary: Subject: *.redtube.com Issuer: DigiCert SHA2 High Assurance Server CA Expiratio...
Certificate summary - Owner: VeriSign Class 3 Public Primary Certification Authority - G5, "(c) 2006...
How to view the ASN.1 structure of an RSA public key using the OpenSSL "asn1parse" command? You can ...