如何在Apache和IIS配置自签名SSL证书并适配多设备连接
Let’s walk through getting this working properly—you were on the right track but missed a few critical steps (especially signing the device certificate with your root CA) and likely need to tweak certificate extensions to support Windows CE’s strict requirements. Here’s a complete, tested workflow:
1. First: Create a Root CA with Compatible Extensions
Windows CE and modern servers expect specific certificate extensions, so we’ll use a config file to avoid missing them. Create a file named rootCA.cnf with this content:
[req] default_bits = 2048 prompt = no default_md = sha256 distinguished_name = dn x509_extensions = v3_ca [dn] C = US # Update with your country ST = YourState # Update with your state L = YourCity # Update with your city O = YourOrganization # Update with your org name OU = YourDepartment # Update with your dept CN = My Root CA # Friendly name for your root CA [v3_ca] subjectKeyIdentifier = hash authorityKeyIdentifier = keyid:always,issuer basicConstraints = critical,CA:true keyUsage = critical,digitalSignature,keyCertSign,cRLSign
Now generate your root CA key and certificate:
# Generate root CA key (use the -des3 flag if you want password protection) openssl genrsa -out rootCA.key 2048 # Generate self-signed root CA certificate openssl req -x509 -new -nodes -key rootCA.key -config rootCA.cnf -sha256 -days 1024 -out rootCA.pem
2. Generate Server/Device Certificate & CSR
Next, create a config file for your server certificate (server.cnf)—this ensures it works with Apache, IIS, Linux, and Windows CE by including Subject Alternative Names (SAN) and correct key usage:
[req] default_bits = 2048 prompt = no default_md = sha256 distinguished_name = dn req_extensions = req_ext [dn] C = US ST = YourState L = YourCity O = YourOrganization OU = YourDepartment CN = your-server.example.com # Match your server's domain/IP [req_ext] subjectAltName = @alt_names keyUsage = critical,digitalSignature,keyEncipherment extendedKeyUsage = serverAuth,clientAuth # Supports both server and client auth [alt_names] DNS.1 = your-server.example.com # Add your domain DNS.2 = www.your-server.example.com # Add any aliases IP.1 = 192.168.1.100 # Add your server's IP if devices connect via IP (critical for Windows CE)
Generate the server key and CSR:
# Generate server private key openssl genrsa -out device.key 2048 # Generate CSR using the config file openssl req -new -key device.key -config server.cnf -out device.csr
3. Sign the Server Certificate with Your Root CA
This is the step you didn’t finish. Run this command to sign your server CSR with the root CA, preserving the extensions from your server.cnf:
openssl x509 -req -in device.csr -CA rootCA.pem -CAkey rootCA.key -CAcreateserial -out device.crt -days 365 -sha256 -extfile server.cnf -extensions req_ext
4. Configure for Apache, IIS, Linux, and Windows CE
Apache Setup
Copy device.crt, device.key, and rootCA.pem to your Apache config directory, then update your virtual host:
SSLEngine On SSLCertificateFile /path/to/device.crt SSLCertificateKeyFile /path/to/device.key SSLCACertificateFile /path/to/rootCA.pem # Optional: Use if you need client certificate validation
IIS Setup
IIS uses PFX (PKCS#12) files, so convert your certificate and key to this format:
openssl pkcs12 -export -out device.pfx -inkey device.key -in device.crt -certfile rootCA.pem
Then:
- Open IIS Manager → Your Server → Server Certificates
- Click "Import" → Select
device.pfx→ Enter the export password you set - Bind the certificate to your website’s HTTPS port
Linux Device Trust
To get Linux devices to trust your root CA:
# Copy root CA to system certs directory sudo cp rootCA.pem /usr/local/share/ca-certificates/my-root-ca.crt # Update trusted certs sudo update-ca-certificates
Windows CE Device Trust
Windows CE has strict certificate requirements—here’s how to make it work:
- Convert your root CA to DER format (Windows CE prefers this):
openssl x509 -in rootCA.pem -out rootCA.cer -outform DER - Transfer
rootCA.certo your Windows CE device (via ActiveSync, SD card, etc.) - On the device: Go to Settings → System → Certificates → Import the
rootCA.cerinto the Trusted Root Certification Authorities store - Ensure the server’s domain/IP matches the CN or SAN in
device.crt—Windows CE will reject certificates with mismatched names
Troubleshooting Your Original Issue
Your main problem was the incomplete openssl x509 command—you didn’t specify the root CA details or include the necessary extensions. Other potential pitfalls:
- Missing SAN entries: Modern devices (including Windows CE) require SANs instead of relying solely on the CN field
- Incorrect key usage: Windows CE needs the
serverAuthextended key usage to trust the certificate for HTTPS - Unrooted CA: Linux and Windows CE won’t trust your server certificate unless they have your root CA in their trusted stores
内容的提问来源于stack exchange,提问作者Omid H

