1.携带crl分发点的证书
openssl ca -extensions v3_ca -in ./demoCA/user1.csr -out ./demoCA/rsa1.pem -days 3650 -CAcreateserial -CA ./demoCA/cacert.pem -CAkey ./demoCA/private/cakey.pem -CAserial serial -extfile ./demoCA/mycrl.cnf
mycrl.cnf文件内容:
crlDistributionPoints=URI:http://192.168.120.61/cacert.crl
(URI填写一个http服务器,用于下载crl文件)
2.携带AIA扩展,用于测试ocspstapling的证书
========中级CA签发==============
1、生成rsaCA 证书
openssl genrsa -des3 -out ./demoCA/private/cakey.pem 2048 #生成CA密钥(私钥)
openssl req -new -days 3650 -key ./demoCA/private/cakey.pem