您的位置:首页 > 运维架构 > Shell

shell完成自动部署CA自签服务器搭建

2014-06-24 14:53 281 查看
#!/bin/bash
# Function: This script is made for auto create ca .
# made by : zhiwang.wang
# contact: jishuweiwang.blog.51cto.com

#create server-point private key
openssl genrsa 2048 > server.key ; chmod 600 server.key
# anther command: (umask 077; openssl genrsa -out server2.key 1024)

# produce public key from server-point private key
openssl rsa -in server.key -pubout > public.key

# produce self-signed certificate from server-point private key
echo "CN
BJ
BJ
DreamGame
Tech
ca.dreamingame.com
caadmin"|openssl req -new -x509 -key server.key -out server.crt -days 365

# modify openssl config file , it only effect when use for CA.
cd /etc/pki/tls/
sed -i '/countryName_default/s#XX#CN#g' openssl.cnf
sed -i 's#Default City#BJ#g' openssl.cnf
sed -i 's#Default Company Ltd#DreamGame#g' openssl.cnf
sed -i '/ProvinceName_default/c\stateOrProvinceName_default     = BJ' openssl.cnf
sed -i '/UnitName_default/c\organizationalUnitName_default  = Tech' openssl.cnf

cd /etc/pki/CA/
(umask 077; openssl genrsa -out private/cakey.pem 2048)

echo "

ca.dreamingame.com
caadmin
" |openssl req -new -x509 -key private/cakey.pem -out cacert.pem

touch index.txt serial
echo 01 > serial

# End
客户端自动申请脚本待续:
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签:  部署 shell openssl