Ubuntu平台下将三类证书文件转换为Nginx所需.cert与.key格式的方法
Got it, let's walk through this step by step to get your SSL certificates ready for Nginx. Here's exactly what you need to do:
1. Create yourdomain.cert (Certificate Chain)
Nginx needs a combined certificate chain file that includes your server certificate, intermediate certificate, and root certificate. The order matters here—always put your server certificate first, followed by the intermediate, then the root.
Run this command in your terminal to concatenate the files:
cat serverCertificate.txt intermediateCertificate.txt rootcertificate.txt > yourdomain.cert
This creates a single file that tells browsers and clients the full trust chain for your SSL certificate, ensuring it's recognized as valid.
2. Extract yourdomain.key (Private Key)
Your private key is almost certainly embedded in the serverCertificate.txt file. It will be wrapped in lines like -----BEGIN PRIVATE KEY----- and -----END PRIVATE KEY----- (or RSA PRIVATE KEY for older keys).
Use this sed command to extract just the private key section:
# For standard private keys sed -n '/-----BEGIN PRIVATE KEY-----/,/-----END PRIVATE KEY-----/p' serverCertificate.txt > yourdomain.key # If your key is an RSA private key, use this instead: sed -n '/-----BEGIN RSA PRIVATE KEY-----/,/-----END RSA PRIVATE KEY-----/p' serverCertificate.txt > yourdomain.key
Verify the Files
Before using them in Nginx, double-check that the files are valid:
- Check the certificate chain (this will display the certificate details if it's valid):
openssl x509 -in yourdomain.cert -text -noout - Check the private key (this will confirm it's not corrupted):
openssl rsa -in yourdomain.key -check
If both commands run without errors, you're ready to configure Nginx with these files!
内容的提问来源于stack exchange,提问作者Hrishikesh

