Differences
This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revision Both sides next revision | ||
project:pki [2017/09/04 19:09] licho [CA na CentOS 7] |
project:pki [2017/09/04 22:38] licho [Linky] |
||
---|---|---|---|
Line 58: | Line 58: | ||
==== CA na CentOS 7 ==== | ==== CA na CentOS 7 ==== | ||
- | Přepokládejme dva servery ca.labka.cz (192.168.1.11), na kterém provozujem Certifikační Autoritu, a ldap.labka.cz (192.168.1.12), na kterém provozujem [[http://directory.fedoraproject.org/|389 Directory Server]]. | + | Přepokládejme dva servery: |
+ | * ca.labka.cz (192.168.1.11), na kterém provozujem Certifikační Autoritu [[https://www.openssl.org/|OpenSSL]], | ||
+ | * a ldap.labka.cz (192.168.1.12), na kterém provozujem LDAP Server [[http://directory.fedoraproject.org/|389 Directory Server]] nebo [[http://www.openldap.org/|OpenLDAP]]. | ||
<code sh create-certs-CA.sh> | <code sh create-certs-CA.sh> | ||
Line 66: | Line 68: | ||
# 2> Vytvoř kořenovou CA: | # 2> Vytvoř kořenovou CA: | ||
- | $ openssl req-x509 -newkey rsa:4096 -keyout myCA.key -out myCA.pem -days 3650 \ | + | $ openssl req -x509 -newkey rsa:4096 -keyout myCA.key -out myCA.pem -days 3650 \ |
-subj "/C=CZ/L=Ostrava/O=Labka/OU=Infra/CN=ca.labka.cz/emailAddress=admin@admin" \ | -subj "/C=CZ/L=Ostrava/O=Labka/OU=Infra/CN=ca.labka.cz/emailAddress=admin@admin" \ | ||
-passout file:passwd | -passout file:passwd | ||
Line 124: | Line 126: | ||
$ adtool list 'ou=People,dc=labka,dc=cz' | $ adtool list 'ou=People,dc=labka,dc=cz' | ||
</code> | </code> | ||
+ | ==== Linky ==== | ||
+ | [[http://henning.kropponline.de/2014/09/14/openldap-setup-w-ca-signed-certificate-centos/|]] | ||
+ | [[https://www.openssl.org/docs/man1.0.2/apps/x509v3_config.html|]] |