Sep 11, 2018 The first thing to do would be to generate a 2048-bit RSA key pair locally. This pair will contain both your private and public key. You can use Java key tool or some other tool, but we will be working with OpenSSL. To generate a public and private key with a certificate signing request (CSR), run the following OpenSSL command.
Generate a certificate signing request
Before you can install a Secure Socket Layer (SSL) certificate, you must first generate a certificate signing request (CSR). You can do this by using one of the following methods:
OpenSSL
The following sections describe how to use OpenSSL to generate a CSR for a single host name. If you want to generate a CSR for multiple host names, we recommend using the Cloud Control Panel or the MyRackspace Portal.
Install OpenSSL
Check whether OpenSSL is installed by using the following command:
If the preceding packages are not returned, install OpenSSL by running the following command:
Generate the RSA keyGenerate Certificate Using Openssl Private Key Generate
Run the following commands to create a directory in which to store your RSA key, substituting a directory name of your choice:
Run the following command to generate a private key:
Create a CSR
Run the following command to create a CSR with the RSA private key (output is in Privacy-Enhanced Mail (PEM) format):
When prompted, enter the necessary information for creating a CSR by using the conventions shown in the following table.
Note: You cannot use the following characters in the Organization Name or Organizational Unit fields:
< > ~ ! @ # $ % ^ * / ( ) ? . , &
Warning: Leave the challenge password blank (press Enter).
Verify your CSROpenssl Generate Private Key Csr
Run the following command to verify your CSR:
After you have verified your CSR, you can submit it to a CA to purchase an SSL certificate.
Windows IIS Manager
Use the following steps to generate a CSR by using Windows IIS Manager:
Note: The following steps are for IIS 8 or IIS 8.5 on Windows Server 2012.
After you have generated the CSR, you can submit it to a CA to purchase an SSL certificate.
Cloud Control Panel
Rackspace provides the CSR Generator for generating a CSR. The CSR Generator shows you the CSRs that you currently have and lets you create new CSRs with a simple form. After you have entered your details, the generator combines them with your private key so that you can submit the combined encoded information to a CA.
When you are done with the generator, you can return to the Cloud Control Panel by clicking any of the links in the top navigation or by going to login.rackspace.com and selecting Rackspace Cloud from the drop-down product menu in the top navigation bar.
Access the CSR Generator
Access the CSR Generator directly or through the Control Panel by using the following steps:
Openssl Generate Rsa Private Key
The generator lists your existing CSRs, if you have any, organized by domain name.
Generate a CSR
It can take between 5 and 60 seconds for the CSR to be generated. You might need to refresh the page that displays your CSRs before the new CSR is listed.
View CSR details
When CSR has been generated, you can click its UUID (unique identifier) in the CSR list to view its details screen.
This screen displays the information that you provided, the text of the CSR, and its associated private key.
Submit the CSR to the CA
The text in the Certificate Request field is the CSR. It contains encoded details of the CSR and your public key.
To request your SSL certificate, copy the Certificate Request text and submit it to your CA. Include all the text, including the BEGIN and END lines at the beginning and end of the text block.
Install the private key
Copy the private key to the server that will host the certificate. See your application documentation to determine where to install the private key and certificate on your server.
MyRackspace Portal
If you are a Managed or Dedicated customer, you can request a CSR through the MyRackspace Portal by using the following steps:
Next stepsReferenceExperience what Rackspace has to offer.
©2020 Rackspace US, Inc.
Except where otherwise noted, content on this site is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License
Common OpenSSL Commands with Keys and CertificatesGenerate RSA private key with certificate in a single commandGenerate Certificate Signing Request (CSR) from private key with passphraseGenerate RSA private key (2048 bit)Generate a Certificate Signing Request (CSR)Generate RSA private key (2048 bit) and a Certificate Signing Request (CSR) with a single commandConvert private key to PEM formatGenerate a self-signed certificate that is valid for a year with sha256 hashView details of a RSA private keyView details of a CSRView details of a CertificateView details of a Certificate in DER formatOpenssl Generate Certificate And Private KeyConvert a DER file (.crt .cer .der) to PEMGenerate Certificate From Private Key OpensslConvert a PEM file to DERComments are closed.
|
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |