generated from GamingChaos/docker-compose
add san to certificates
This commit is contained in:
@@ -1,12 +1,23 @@
|
||||
|
||||
[ -d ssl ] || mkdir ssl
|
||||
sudo rm -rf ./ssl ; mkdir ssl
|
||||
cd ssl
|
||||
|
||||
# create root ca
|
||||
openssl req -x509 -newkey rsa:8192 -keyout ca.key -out ca.crt -days 36500 -nodes -subj "/CN=LGTM CA"
|
||||
hostname=$(hostname).stuyckv.local
|
||||
|
||||
openssl req -new -newkey rsa:2048 -nodes -keyout server.key -out server.csr -subj "/CN=$(hostname).stuyckv.local"
|
||||
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out server.crt -days 365
|
||||
echo "subjectAltName=DNS:shion.stuyckv.local,DNS:localhost,IP:127.0.0.1" > shion.san
|
||||
# create root ca
|
||||
openssl req -x509 -newkey rsa:8192 \
|
||||
-keyout ca.key -out ca.crt \
|
||||
-days 36500 -nodes -subj "/CN=LGTM CA"
|
||||
|
||||
openssl req -new -newkey rsa:2048 \
|
||||
-keyout server.key -out server.csr \
|
||||
-nodes -subj "/CN=$hostname"
|
||||
openssl x509 -req -CAcreateserial \
|
||||
-in server.csr -out server.crt \
|
||||
-CA ca.crt -CAkey ca.key \
|
||||
-days 365 -extfile shion.san
|
||||
cat ca.crt >> server.crt
|
||||
|
||||
sudo chown 10001:10001 ./server.key ./server.crt ./ca.crt
|
||||
|
||||
|
||||
Reference in New Issue
Block a user