You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RHEL中使用OpenSSL:不依赖openssl.cnf实现根证书签客户端证书

PKI自签名架构脚本优化与问题解答

Let's break this down step by step to address your questions and refine your scripts to meet the given constraints.


1. 当前客户端证书签署命令是否正确?

Nope, there are several issues with your current client signing command and surrounding script:

  • Variable syntax & typo errors: {$clientName} should be ${clientName}, you've got typos like privat.key (missing an 'e' → private.key) and ec-secp384rp1.pem (typo → ec-secp384r1.pem).
  • Unused variable: You collect rkAssoc but don't actually use it in the signing command—this defeats the purpose of associating the client cert with a specific root key.
  • Incorrect output naming: The output of openssl ca is a signed certificate, not a private key. Naming it _signedprivatekey.pem is misleading; it should be something like ${clientName}.crt.
  • Missing password handling: You mentioned needing to collect the client key password, but the current script doesn't include -passout (for setting the key password) or -passin (if needed for the root key).
  • Config dependency: Without overriding config values via command line, the openssl ca command will default to whatever's set in your openssl.cnf, which doesn't let you pick a specific root key dynamically.

2. 是否可通过命令行参数替代openssl.cnf中的配置,直接指定根证书进行签署?

Absolutely! The openssl ca command supports a wide range of command-line flags that let you override settings from the config file, so you never need to modify openssl.cnf dynamically. Key flags you'll need include:

  • -cert: Path to the root CA certificate you want to use for signing
  • -keyfile: Path to the corresponding root CA private key
  • -serial: Path to a unique serial number file for this root CA (avoids conflicts between different roots)
  • -database: Path to a certificate database file for this root CA (tracks issued certs)
  • -outdir: Directory to store output files (can override the config's default)

You can also keep using -extensions usr_cert and -policy policy_anything directly in the command as long as your config defines that policy (which it likely does).


优化后的脚本示例

根密钥及证书生成脚本

This script collects user input for paths/names, generates the root CA pair, and creates necessary tracking files for future client signing (so each root has its own independent records):

#!/bin/bash

# Collect user input
read -p "Enter absolute directory to store root CA files: " userdir
read -p "Enter root CA name (will be used in filenames): " rootName

# Create directory if it doesn't exist
mkdir -p "$userdir"

# Generate root EC key and self-signed cert
openssl req -new -x509 -days 3652 -nodes -sha384 \
  -newkey ec:ec-secp384r1.pem \
  -keyout "${userdir}/${rootName}_private.key" \
  -out "${userdir}/${rootName}.crt" \
  -subj "/CN=${rootName} Root CA/O=YourOrg/C=US"

# Create required files for openssl ca (avoids modifying openssl.cnf)
touch "${userdir}/${rootName}.serial"
echo "01" > "${userdir}/${rootName}.serial"
touch "${userdir}/${rootName}.index.txt"

echo "Root CA generated successfully! Files stored in ${userdir}"
echo "Serial file: ${userdir}/${rootName}.serial"
echo "Database file: ${userdir}/${rootName}.index.txt"

客户端密钥及证书生成脚本

This script lets users pick an existing root CA, collects client details/passwords, and signs the client CSR without touching openssl.cnf:

#!/bin/bash

# Collect user input
read -p "Enter absolute directory to store client files: " clientdir
read -p "Enter client name (will be used in filenames): " clientName
read -p "Enter password for client private key: " -s clientPass
echo
read -p "Enter absolute path to root CA private key (e.g., /opt/ca/root1_private.key): " rkAssoc

# Derive related root CA file paths automatically
rootCert="${rkAssoc/_private.key/.crt}"
rootDir=$(dirname "$rkAssoc")
rootName=$(basename "$rkAssoc" _private.key)
serialFile="${rootDir}/${rootName}.serial"
dbFile="${rootDir}/${rootName}.index.txt"

# Create client directory if it doesn't exist
mkdir -p "$clientdir"

# Generate client EC key and CSR (with password protection)
openssl req -newkey ec:ec-secp384r1.pem -sha384 \
  -keyout "${clientdir}/${clientName}_private.key" \
  -out "${clientdir}/${clientName}.csr" \
  -subj "/CN=${clientName}/O=YourOrg/C=US" \
  -passout pass:"${clientPass}"

# Sign client CSR with the selected root CA (override config via command line)
openssl ca -config /etc/pki/tls/openssl.cnf \
  -policy policy_anything \
  -extensions usr_cert \
  -days 730 \
  -notext \
  -md sha384 \
  -in "${clientdir}/${clientName}.csr" \
  -out "${clientdir}/${clientName}.crt" \
  -cert "${rootCert}" \
  -keyfile "${rkAssoc}" \
  -serial "${serialFile}" \
  -database "${dbFile}" \
  -outdir "${clientdir}"

echo "Client certificate signed successfully! Files stored in ${clientdir}"
echo "Client private key: ${clientdir}/${clientName}_private.key"
echo "Signed client cert: ${clientdir}/${clientName}.crt"

关键优势

  • No dynamic modification of openssl.cnf or scripts between runs
  • Supports multiple root CAs, and users can pick which one to use for each client cert
  • All root-specific tracking (serial, database) is stored alongside the root key, avoiding conflicts
  • Handles client key passwords as required

内容的提问来源于stack exchange,提问作者CharlieTango92

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:56:20