OpenSSL - Create a Self Signed Document Signing certificate based on an external CSR
- Install OpenSSL
1
yum install openssl - Edit /etc/pki/tls/openssl.cnf and change the [policy_match] and make all optional
- Create CA
1
openssl req -new -x509 -days 365 -key /etc/pki/CA/private/cakey.pem -out /etc/pki/CA/certs/cacert.pem
Country Name (2 letter code) [XX]:AE
State or Province Name (full name) []:Dubai
Locality Name (eg, city) [Default City]:DSO
Organization Name (eg, company) [Default Company Ltd]:My Company
Organizational Unit Name (eg, section) []:IT
Common Name (eg, your name or your server’s hostname) []:My Company CA
Email Address []:me@mycompany.com
4. Create index & serial file. Remove all lines from this if already exists.
1
2
touch /etc/pki/CA/index.txt
echo '1000' > /etc/pki/CA/serial
If you don’t have a CSR run the commands below to create a certificate.
1
openssl req -utf8 -nameopt oneline,utf8 -new -key username_key.pem -out username_req.pem
1
openssl x509 -days 365 -CA /etc/pki/CA/cacert.pem -CAkey /etc/pki/CA/private/cakey.pem -CAserial /etc/pki/CA/serial -in username_req.pem -req -out username.pem
1
openssl pkcs12 -export -in username.pem -inkey username_key.pem -out username.p12
You can use this file(username.p12) to test digitally signing a pdf using acrobat reader.
If you have an external CSR and you want to supply a certificate using that CSR run the below command. Here the CSR file is “dsa_csr_ad.txt”
1
openssl ca -cert /etc/pki/CA/cacert.pem -keyfile /etc/pki/CA/private/cakey.pem -in dsa_csr_ad.txt -out shyju_cert_ad.pem
Self Signed certificates will always show at least one signature has problems. You have to manually trust it to show as valid.
OS Used : CentOS 7

