Registrants & Certificates
Generate a TLS Certificate
With the CA private key already
With the CA private key alreadyVerify Client Certificate Requirements:
openssl s_client -connect 10.10.10.131:443Generate the client's private key:
openssl genrsa -out client.key 4096Create a
certificate signing request (CSR), ensure the fields match the server's expectations:
openssl req -new -key client.key -out client.reqSign the
CSRwith theCA’s private keyto issue aclient certificate:
openssl x509 -req -in client.req -CA lacasadepapel-htb.pem -CAkey ca.key -set_serial 101 -extensions client -days 365 -outform PEM -out client.cerConvert the private key and certificate into a
PKCS#12 (.p12)format file for easy import:
openssl pkcs12 -export -inkey client.key -in client.cer -out client.p12Last updated