You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用OpenSSL创建由自有可信中间证书签名的负载均衡器TLS证书

Alright, let's walk through exactly how to generate a new TLS certificate for your load balancer that's signed by your trusted intermediate CA using OpenSSL. I'll break this down into straightforward, actionable steps with explanations so you don't get stuck.

Step 1: Generate a Certificate Signing Request (CSR) and Private Key for the Load Balancer

First, you need to create a unique private key and CSR for your load balancer. You have two common options for encryption algorithms—pick whichever fits your needs:

Option A: RSA (Widely Compatible)

openssl req -new -newkey rsa:2048 -nodes -keyout lb-private-key.pem -out lb-csr.pem
  • -nodes: Skips encrypting the private key (so your load balancer can auto-load it without a passphrase; remove this flag if you want encrypted key security)
  • When prompted, fill in the certificate details. The Common Name is critical—this should match your load balancer's domain name or public IP address.

Option B: ECDSA (More Efficient, Modern)

If you prefer a faster, smaller key (equivalent security to RSA with fewer bits), use ECDSA:

openssl req -new -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -nodes -keyout lb-private-key.pem -out lb-csr.pem

Same note about the Common Name applies here.

Step 2: Sign the CSR with Your Intermediate CA

Now use your intermediate CA's key and certificate to sign the load balancer's CSR. I'll cover two scenarios—basic signing, and a recommended approach with custom TLS extensions.

Basic Signing (No Custom Extensions)

If you don't need special TLS features (like multi-domain support), run this command:

openssl x509 -req -in lb-csr.pem -CA intermediate-cert.pem -CAkey intermediate-private-key.pem -CAcreateserial -out lb-certificate.pem -days 365
  • Replace intermediate-cert.pem and intermediate-private-key.pem with your actual intermediate CA file names
  • -CAcreateserial: Generates a serial number file (intermediate-cert.srl) to track signed certificates (it will auto-increment for future signings)
  • -days 365: Sets the certificate validity to 1 year—adjust this to fit your security policy.

TLS certificates work best with specific extensions (like subjectAltName for multi-domain support, or proper key usage flags). Create a config file (e.g., intermediate-sign-config.cnf) with these settings:

[req]
default_bits = 2048
distinguished_name = req_distinguished_name
req_extensions = req_ext

[req_distinguished_name]
countryName = Country Name (2 letter code)
countryName_default = US
stateOrProvinceName = State or Province Name (full name)
stateOrProvinceName_default = California
localityName = Locality Name (eg, city)
localityName_default = San Francisco
organizationName = Organization Name (eg, company)
organizationName_default = Example Corp
commonName = Common Name (e.g. server FQDN or YOUR name)
commonName_default = lb.yourdomain.com

[req_ext]
subjectAltName = @alt_names
keyUsage = digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth, clientAuth

[alt_names]
DNS.1 = lb.yourdomain.com
DNS.2 = www.yourdomain.com
IP.1 = 192.168.1.100  # Add your load balancer's IP if needed

Then sign the CSR using this config:

openssl x509 -req -in lb-csr.pem -CA intermediate-cert.pem -CAkey intermediate-private-key.pem -CAcreateserial -out lb-certificate.pem -days 365 -extfile intermediate-sign-config.cnf -extensions req_ext
Step 3: Verify the Signed Certificate

Before deploying it to your load balancer, confirm the certificate is valid and properly signed:

# View full certificate details to check extensions and issuer
openssl x509 -in lb-certificate.pem -text -noout

# Validate the certificate against your intermediate CA
openssl verify -CAfile intermediate-cert.pem lb-certificate.pem

If you see lb-certificate.pem: OK, you're good to go.

Step 4: Prepare Files for the Load Balancer

Most load balancers require:

  1. The load balancer's private key (lb-private-key.pem)
  2. The signed certificate (lb-certificate.pem)
  3. The intermediate CA certificate (for full chain validation)

Many load balancers accept a combined "full chain" file (server certificate first, followed by intermediate CA):

cat lb-certificate.pem intermediate-cert.pem > lb-fullchain.pem

Now you can use lb-fullchain.pem and lb-private-key.pem in your load balancer's TLS settings.


内容的提问来源于stack exchange,提问作者Dave MacDonald

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:51:29