如何使用OpenSSL创建由自有可信中间证书签名的负载均衡器TLS证书
Alright, let's walk through exactly how to generate a new TLS certificate for your load balancer that's signed by your trusted intermediate CA using OpenSSL. I'll break this down into straightforward, actionable steps with explanations so you don't get stuck.
First, you need to create a unique private key and CSR for your load balancer. You have two common options for encryption algorithms—pick whichever fits your needs:
Option A: RSA (Widely Compatible)
openssl req -new -newkey rsa:2048 -nodes -keyout lb-private-key.pem -out lb-csr.pem
-nodes: Skips encrypting the private key (so your load balancer can auto-load it without a passphrase; remove this flag if you want encrypted key security)- When prompted, fill in the certificate details. The Common Name is critical—this should match your load balancer's domain name or public IP address.
Option B: ECDSA (More Efficient, Modern)
If you prefer a faster, smaller key (equivalent security to RSA with fewer bits), use ECDSA:
openssl req -new -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -nodes -keyout lb-private-key.pem -out lb-csr.pem
Same note about the Common Name applies here.
Now use your intermediate CA's key and certificate to sign the load balancer's CSR. I'll cover two scenarios—basic signing, and a recommended approach with custom TLS extensions.
Basic Signing (No Custom Extensions)
If you don't need special TLS features (like multi-domain support), run this command:
openssl x509 -req -in lb-csr.pem -CA intermediate-cert.pem -CAkey intermediate-private-key.pem -CAcreateserial -out lb-certificate.pem -days 365
- Replace
intermediate-cert.pemandintermediate-private-key.pemwith your actual intermediate CA file names -CAcreateserial: Generates a serial number file (intermediate-cert.srl) to track signed certificates (it will auto-increment for future signings)-days 365: Sets the certificate validity to 1 year—adjust this to fit your security policy.
Recommended: Sign with Custom TLS Extensions
TLS certificates work best with specific extensions (like subjectAltName for multi-domain support, or proper key usage flags). Create a config file (e.g., intermediate-sign-config.cnf) with these settings:
[req] default_bits = 2048 distinguished_name = req_distinguished_name req_extensions = req_ext [req_distinguished_name] countryName = Country Name (2 letter code) countryName_default = US stateOrProvinceName = State or Province Name (full name) stateOrProvinceName_default = California localityName = Locality Name (eg, city) localityName_default = San Francisco organizationName = Organization Name (eg, company) organizationName_default = Example Corp commonName = Common Name (e.g. server FQDN or YOUR name) commonName_default = lb.yourdomain.com [req_ext] subjectAltName = @alt_names keyUsage = digitalSignature, keyEncipherment extendedKeyUsage = serverAuth, clientAuth [alt_names] DNS.1 = lb.yourdomain.com DNS.2 = www.yourdomain.com IP.1 = 192.168.1.100 # Add your load balancer's IP if needed
Then sign the CSR using this config:
openssl x509 -req -in lb-csr.pem -CA intermediate-cert.pem -CAkey intermediate-private-key.pem -CAcreateserial -out lb-certificate.pem -days 365 -extfile intermediate-sign-config.cnf -extensions req_ext
Before deploying it to your load balancer, confirm the certificate is valid and properly signed:
# View full certificate details to check extensions and issuer openssl x509 -in lb-certificate.pem -text -noout # Validate the certificate against your intermediate CA openssl verify -CAfile intermediate-cert.pem lb-certificate.pem
If you see lb-certificate.pem: OK, you're good to go.
Most load balancers require:
- The load balancer's private key (
lb-private-key.pem) - The signed certificate (
lb-certificate.pem) - The intermediate CA certificate (for full chain validation)
Many load balancers accept a combined "full chain" file (server certificate first, followed by intermediate CA):
cat lb-certificate.pem intermediate-cert.pem > lb-fullchain.pem
Now you can use lb-fullchain.pem and lb-private-key.pem in your load balancer's TLS settings.
内容的提问来源于stack exchange,提问作者Dave MacDonald

