make_certs.sh 1.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364
  1. #!/bin/sh
  2. #using "pass" for every password
  3. echo "Generating client certificate ..."
  4. openssl genrsa -des3 -out client.key 2048
  5. openssl req -new -key client.key -out client.csr
  6. cp client.key client.key.orig
  7. openssl rsa -in client.key.orig -out client.key
  8. openssl x509 -req -days 3650 -in client.csr -signkey client.key -out client.crt
  9. cp client.crt client.pem
  10. cat client.key >> client.pem
  11. openssl pkcs12 -export -inkey client.key -in client.pem -name ClientName -out client.pfx
  12. echo "Generating first server certificate ..."
  13. openssl genrsa -des3 -out server.key 2048
  14. openssl req -new -key server.key -out server.csr
  15. cp server.key server.key.orig
  16. openssl rsa -in server.key.orig -out server.key
  17. openssl x509 -req -days 3650 -in server.csr -signkey server.key -out server.crt
  18. cp server.crt server.pem
  19. cat server.key >> server.pem
  20. openssl pkcs12 -export -inkey server.key -in server.pem -name ServerName -out server.pfx
  21. echo "First server certificate hash for Public-Key-Pins header:"
  22. openssl x509 -pubkey < server.crt | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | base64 > server.pin
  23. cat server.pin
  24. echo "Generating backup server certificate ..."
  25. openssl genrsa -des3 -out server_bkup.key 2048
  26. openssl req -new -key server_bkup.key -out server_bkup.csr
  27. cp server_bkup.key server_bkup.key.orig
  28. openssl rsa -in server_bkup.key.orig -out server_bkup.key
  29. openssl x509 -req -days 3650 -in server_bkup.csr -signkey server_bkup.key -out server_bkup.crt
  30. cp server_bkup.crt server_bkup.pem
  31. cat server_bkup.key >> server_bkup.pem
  32. openssl pkcs12 -export -inkey server_bkup.key -in server_bkup.pem -name ServerName -out server_bkup.pfx
  33. echo "Backup server certificate hash for Public-Key-Pins header:"
  34. openssl x509 -pubkey < server_bkup.crt | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | base64 > server_bkup.pin
  35. cat server_bkup.pin