Generar un certificado firmado por CA
El servicio de daemon SnapDrive para UNIX requiere que se genere un certificado firmado por CA para que la comunicación se realice correctamente. Debe proporcionar el certificado firmado por CA en la ruta especificada en snapdrive.conf
archivo.
-
Debe iniciar sesión como usuario raíz.
-
Debe haber configurado los siguientes parámetros en el
snapdrive.conf
Archivo que se va a utilizar HTTPS para la comunicación:-
use-https-to-sdu-daemon=on
-
contact-https-port-sdu-daemon=4095
-
sdu-daemon-certificate-path=
/opt/NetApp/snapdrive/snapdrive.pem
-
-
Generar una nueva clave privada RSA sin cifrar en formato pem:
$ openssl genrsa -out privkey.pem 1024
Generating RSA private key, 1024 bit long modulus ....................++++++ ....................................++++++ e is 65537 (0x10001)
-
Configurar
/etc/ssl/openssl.cnf
Para crear la clave privada de CA y el certificado vi/etc/ssl/openssl.cnf
. -
Cree un certificado sin firmar utilizando su clave privada RSA:
$ openssl req -new -x509 -key privkey.pem -out cert.pem
You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields there will be a default value, If you enter '.', the field will be left blank. ----- Country Name (2 letter code) [XX]:NY State or Province Name (full name) []:Nebraska Locality Name (eg, city) [Default City]:Omaha Organization Name (eg, company) [Default Company Ltd]:abc.com Organizational Unit Name (eg, section) []: Common Name (eg, your name or your server's hostname) []:localhost Email Address []:abc@example.org
-
Utilice su clave privada y su certificado para crear una CSR:
cat cert.pem privkey.pem | openssl x509 -x509toreq -signkey privkey.pem -out certreq.csr
Getting request Private Key Generating certificate request
-
Firme el certificado con la clave privada de CA mediante la CSR que acaba de crear:
$ openssl ca -in certreq.csr -out newcert.pem
Using configuration from /etc/pki/tls/openssl.cnf Check that the request matches the signature Signature ok Certificate Details: Serial Number: 4096 (0x1000) Validity Not Before: May 17 06:02:51 2015 GMT Not After : May 16 06:02:51 2016 GMT Subject: countryName = NY stateOrProvinceName = Nebraska organizationName = abc.com commonName = localhost emailAddress = abc@example.org X509v3 extensions: X509v3 Basic Constraints: CA:FALSE X509v3 Key Usage: Digital Signature, Non Repudiation, Key Encipherment Netscape Comment: OpenSSL Generated Certificate X509v3 Subject Key Identifier: FB:B0:F6:A0:9B:F2:C2:BC:50:BF:45:B2:9D:DB:AA:3B:C5:07:5B:7F X509v3 Authority Key Identifier: keyid:FB:B0:F6:A0:9B:F2:C2:BC:50:BF:45:B2:9D:DB:AA:3B:C5:07:5B:7F Certificate is to be certified until May 16 06:02:51 2016 GMT (365 days) Sign the certificate? [y/n]:y 1 out of 1 certificate requests certified, commit? [y/n]y Write out database with 1 new entries Data Base Updated
-
Instale el certificado firmado y la clave privada que utilizará un servidor SSL.
The newcert.pem is the certificate signed by your local CA that you can then use in an ssl server: ( openssl x509 -in newcert.pem; cat privkey.pem ) > server.pem ln -s server.pem `openssl x509 -hash -noout -in server.pem`.0 # dot-zero ( server.pem refers to location of https server certificate)