mirror of
https://github.com/OpenVPN/openvpn.git
synced 2024-11-27 19:53:51 +08:00
Add a DSA test key/cert pair to sample-keys
Makes it easier to test changes to DSA-related code. Signed-off-by: Steffan Karger <steffan@karger.me> Acked-by: Gert Doering <gert@greenie.muc.de> Message-Id: <20170618105740.10090-1-steffan@karger.me> URL: https://www.mail-archive.com/search?l=mid&q=20170618105740.10090-1-steffan@karger.me Signed-off-by: Gert Doering <gert@greenie.muc.de>
This commit is contained in:
parent
3fd07c31fe
commit
3d215d4c9d
@ -61,6 +61,22 @@ openssl ca -batch -config openssl.cnf \
|
||||
openssl ca -config openssl.cnf -revoke sample-ca/client-revoked.crt
|
||||
openssl ca -config openssl.cnf -gencrl -out sample-ca/ca.crl
|
||||
|
||||
# Create DSA server and client cert (signed by 'regular' RSA CA)
|
||||
openssl dsaparam -out sample-ca/dsaparams.pem 2048
|
||||
|
||||
openssl req -new -newkey dsa:sample-ca/dsaparams.pem -nodes -config openssl.cnf \
|
||||
-extensions server \
|
||||
-keyout sample-ca/server-dsa.key -out sample-ca/server-dsa.csr \
|
||||
-subj "/C=KG/ST=NA/O=OpenVPN-TEST/CN=Test-Server-DSA/emailAddress=me@myhost.mydomain"
|
||||
openssl ca -batch -config openssl.cnf -extensions server \
|
||||
-out sample-ca/server-dsa.crt -in sample-ca/server-dsa.csr
|
||||
|
||||
openssl req -new -newkey dsa:sample-ca/dsaparams.pem -nodes -config openssl.cnf \
|
||||
-keyout sample-ca/client-dsa.key -out sample-ca/client-dsa.csr \
|
||||
-subj "/C=KG/ST=NA/O=OpenVPN-TEST/CN=Test-Client-DSA/emailAddress=me@myhost.mydomain"
|
||||
openssl ca -batch -config openssl.cnf \
|
||||
-out sample-ca/client-dsa.crt -in sample-ca/client-dsa.csr
|
||||
|
||||
# Create EC server and client cert (signed by 'regular' RSA CA)
|
||||
openssl ecparam -out sample-ca/secp256k1.pem -name secp256k1
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user