]> git.proxmox.com Git - ceph.git/blob - ceph/src/civetweb/resources/cert/make_certs.sh
update sources to ceph Nautilus 14.2.1
[ceph.git] / ceph / src / civetweb / resources / cert / make_certs.sh
1 #!/bin/sh
2 #using "pass" for every password
3
4 echo "Generating client certificate ..."
5
6 openssl genrsa -des3 -out client.key 2048
7 openssl req -new -key client.key -out client.csr
8
9 cp client.key client.key.orig
10
11 openssl rsa -in client.key.orig -out client.key
12
13 openssl x509 -req -days 3650 -in client.csr -signkey client.key -out client.crt
14
15 cp client.crt client.pem
16 cat client.key >> client.pem
17
18 openssl pkcs12 -export -inkey client.key -in client.pem -name ClientName -out client.pfx
19
20
21 echo "Generating first server certificate ..."
22
23 openssl genrsa -des3 -out server.key 2048
24 openssl req -new -key server.key -out server.csr
25
26 cp server.key server.key.orig
27
28 openssl rsa -in server.key.orig -out server.key
29
30 openssl x509 -req -days 3650 -in server.csr -signkey server.key -out server.crt
31
32 cp server.crt server.pem
33 cat server.key >> server.pem
34
35 openssl pkcs12 -export -inkey server.key -in server.pem -name ServerName -out server.pfx
36
37 echo "First server certificate hash for Public-Key-Pins header:"
38
39 openssl x509 -pubkey < server.crt | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | base64 > server.pin
40
41 cat server.pin
42
43 echo "Generating backup server certificate ..."
44
45 openssl genrsa -des3 -out server_bkup.key 2048
46 openssl req -new -key server_bkup.key -out server_bkup.csr
47
48 cp server_bkup.key server_bkup.key.orig
49
50 openssl rsa -in server_bkup.key.orig -out server_bkup.key
51
52 openssl x509 -req -days 3650 -in server_bkup.csr -signkey server_bkup.key -out server_bkup.crt
53
54 cp server_bkup.crt server_bkup.pem
55 cat server_bkup.key >> server_bkup.pem
56
57 openssl pkcs12 -export -inkey server_bkup.key -in server_bkup.pem -name ServerName -out server_bkup.pfx
58
59 echo "Backup server certificate hash for Public-Key-Pins header:"
60
61 openssl x509 -pubkey < server_bkup.crt | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | base64 > server_bkup.pin
62
63 cat server_bkup.pin
64