From f110c617c706e3a0b21daf29802e44668e202740 Mon Sep 17 00:00:00 2001 From: Rob Austein Date: Sun, 21 Aug 2016 15:40:34 -0400 Subject: Split out certificate creation; handle verification properly. --- issue-certificates.sh | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) create mode 100755 issue-certificates.sh (limited to 'issue-certificates.sh') diff --git a/issue-certificates.sh b/issue-certificates.sh new file mode 100755 index 0000000..39e64d9 --- /dev/null +++ b/issue-certificates.sh @@ -0,0 +1,27 @@ +#!/bin/sh - + +. ./environment.sh + +set -x + +openssl req -batch -new -engine pkcs11 -keyform ENGINE -x509 -days 365 \ + -subj "/C=PV/O=Pottsylvanian Ministry of Offense/GN=Fearless/SN=Leader" \ + -key label_leader -out leader.cer + +openssl req -batch -new -engine pkcs11 -keyform ENGINE \ + -subj "/GN=Natasha/SN=Fatale" \ + -key label_natasha | +openssl x509 -req -engine pkcs11 -CAkeyform ENGINE -days 60 \ + -set_serial `date +%s` -extfile $OPENSSL_CONF -extensions ext_ee \ + -CAkey label_leader -CA leader.cer \ + -out natasha.cer + +openssl req -batch -new -engine pkcs11 -keyform ENGINE \ + -subj "/GN=Boris/SN=Badenov" \ + -key label_boris | +openssl x509 -req -engine pkcs11 -CAkeyform ENGINE -days 60 \ + -set_serial `date +%s` -extfile $OPENSSL_CONF -extensions ext_ee \ + -CAkey label_leader -CA leader.cer \ + -out boris.cer + +openssl verify -verbose -CAfile leader.cer boris.cer natasha.cer -- cgit v1.2.3