[root@deyu ~]# cd /etc/pki/CA [root@deyu CA]# mkdir {certs,crl,newcerts} [root@deyu CA]# touch index.txt [root@deyu CA]# echo 01 > serial [root@deyu CA]# openssl req -new -x509 -nodes -out cacert.pem \ -keyout private/cakey.pem \ -subj '/C=TW/ST=Taiwan/L=CYUT/O=CSIE/CN=deyu.wang Certificate Authority'
[root@deyu CA]# cp cacert.pem /etc/pki/tls/certs [root@deyu CA]# chmod 644 /etc/pki/tls/certs/cacert.pem [root@deyu CA]# cp cacert.pem /var/ftp/pub [root@deyu CA]# chmod 644 /var/ftp/pub/cacert.pem
[root@deyu ~]# umask 077 [root@deyu ~]# cd /etc/pki/tls/certs [root@deyu certs]# rm -f slapd.pem [root@deyu certs]# openssl req -new -nodes -out slapd.csr \ -keyout slapd.key -subj '/C=TW/ST=Taiwan/L=CYUT/O=CSIE/CN=deyu.wang' [root@deyu certs]# openssl ca -batch -in slapd.csr -out slapd.crt [root@deyu certs]# ( cat slapd.key; echo; cat slapd.crt ) > slapd.pem [root@deyu certs]# chown ldap slapd.pem [root@deyu certs]# rm -f slapd.key slapd.crt slapd.csr
2015-04-13