View previous topic :: View next topic |
Author |
Message |
dman777 Veteran
data:image/s3,"s3://crabby-images/66e5c/66e5c234886f45e11b41308b8f65d2542e40feb1" alt="Veteran Veteran"
Joined: 10 Jan 2007 Posts: 1004
|
Posted: Mon Dec 14, 2009 6:27 am Post subject: Problem signing a SSL CA certificate |
|
|
I created a SSL CA certificate. Now I am trying to sign it, but I get an error it where it can not find the passkey. What am I doing wrong?
Code: | localhost three # open ssl req -new -nodes -subj '/C=US/ST=Texas/L=Austin' -keyout FOO-key.pem -out FOO-req.pem -days 1095
bash: open: command not found
localhost three # openssl req -new -nodes -subj '/C=US/ST=Texas/L=Austin' -keyout FOO-key.pem -out FOO-req.pem -days 1095
Generating a 1024 bit RSA private key
...++++++
.................++++++
writing new private key to 'FOO-key.pem'
-----
localhost three # openssl ca -out FOO-cert.pem -infiles FOO-req.pem
Using configuration from /etc/ssl/openssl.cnf
Error opening CA private key ./demoCA/private/cakey.pem
13193:error:02001002:system library:fopen:No such file or directory:bss_file.c:356:fopen('./demoCA/private/cakey.pem','r')
13193:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:358:
unable to load CA private key
localhost three #
|
|
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
John R. Graham Administrator
data:image/s3,"s3://crabby-images/a49a9/a49a9a4fe0fe25e0741dcc999a03bccdab82f66e" alt="Administrator Administrator"
data:image/s3,"s3://crabby-images/dbe6a/dbe6afd40417637d1a92f283709e18ed8ab0bc07" alt=""
Joined: 08 Mar 2005 Posts: 10733 Location: Somewhere over Atlanta, Georgia
|
Posted: Mon Dec 14, 2009 10:02 am Post subject: |
|
|
First command should be "openssl", not "open ssl".
- John _________________ I can confirm that I have received between 0 and 499 National Security Letters. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
tuber Apprentice
data:image/s3,"s3://crabby-images/ea29a/ea29a4cbd68e0e1eea77308b308be178c4bce818" alt="Apprentice Apprentice"
Joined: 12 Nov 2004 Posts: 267
|
Posted: Tue Dec 15, 2009 12:32 am Post subject: Re: Problem signing a SSL CA certificate |
|
|
Try Code: | openssl ca -out FOO-cert.pem -infiles FOO-req.pem -keyfile FOO-key.pem |
dman777 wrote: | localhost three # openssl ca -out FOO-cert.pem -infiles FOO-req.pem
Using configuration from /etc/ssl/openssl.cnf
Error opening CA private key ./demoCA/private/cakey.pem
13193:error:02001002:system library:fopen:No such file or directory:bss_file.c:356:fopen('./demoCA/private/cakey.pem','r')
13193:error:20074002:BIO routines:FILE_CTRL:system lib:bss_file.c:358:
unable to load CA private key
localhost three #
[/code] |
|
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
Hu Administrator
data:image/s3,"s3://crabby-images/a49a9/a49a9a4fe0fe25e0741dcc999a03bccdab82f66e" alt="Administrator Administrator"
Joined: 06 Mar 2007 Posts: 23123
|
Posted: Tue Dec 15, 2009 3:14 am Post subject: |
|
|
You may want to use GnuTLS for this instead. It provides certtool to manage certificates, and the info page has a nice step-by-step of how to create a CA, and use it to sign a non-CA certificate. The certificates created this way should be in a standard form, so you can feed them back into applications using OpenSSL. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
DawgG l33t
data:image/s3,"s3://crabby-images/bff5d/bff5df7e25fc71bb7724c77ba91da311c411c1d3" alt="l33t l33t"
data:image/s3,"s3://crabby-images/2c861/2c8619ddab2ee13451f84e90f64e54b0ae6346e9" alt=""
Joined: 17 Sep 2003 Posts: 877
|
Posted: Tue Dec 15, 2009 3:27 pm Post subject: |
|
|
i have experienced a very similar error. make sure the paths you are using are exactly the paths stated in openssl.cnf or adapt openssl.cnf to the paths you want to use. stuff like that can also happen if the index or serial.txt-files are missing.
personally, i like a name different from DemoCA.
GOOD LUCK! _________________ DUMM KLICKT GUT. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
|