root@master01:/home/casa/cer-test# keytool -genkey -alias tlsServer -keysize 2048 -validity 365 -keyalg RSA -dname "CN=localhost" -keypass server -storepass server -keystore server.jks
Warning:
The JKS keystore uses a proprietary format. It is recommended to migrate to PKCS12 which is an industry standard format using "keytool -importkeystore -srckeystore server.jks -destkeystore server.jks -deststoretype pkcs12".
生成服务端自签名证书
root@master01:/home/casa/cer-test# keytool -export -alias tlsServer -keystore server.jks -storepass server -file server.cer
Certificate stored in file <server.cer>
Warning:
The JKS keystore uses a proprietary format. It is recommended to migrate to PKCS12 which is an industry standard format using "keytool -importkeystore -srckeystore server.jks -destkeystore server.jks -deststoretype pkcs12".
生成客户端的密钥对和证书仓库
root@master01:/home/casa/cer-test# keytool -genkey -alias tlsClient -keysize 2048 -validity 365 -keyalg RSA -dname "CN=node01" -keypass client -storepass client -keystore client.jks
Warning:
The JKS keystore uses a proprietary format. It is recommended to migrate to PKCS12 which is an industry standard format using "keytool -impo