Hier werden die Unterschiede zwischen zwei Versionen angezeigt.
| Beide Seiten der vorigen RevisionVorhergehende ÜberarbeitungNächste Überarbeitung | Vorhergehende Überarbeitung | ||
| lx:ucs:ca [02.04.2025 18:03] – how to create a CodeSigning Cert Andy Haubenschmid | lx:ucs:ca [25.07.2026 22:13] (aktuell) – berechnung der Tage in eine Variable schreiben Andy Haubenschmid | ||
|---|---|---|---|
| Zeile 10: | Zeile 10: | ||
| ===== neues Server Zertifikat erstellen ===== | ===== neues Server Zertifikat erstellen ===== | ||
| + | Ausrechnen wie lange das Zertifikat laufen darf, am besten das Ablaufdatum der CA verwenden. | ||
| < | < | ||
| echo \(`date -d 18-Oct-2027 +' | echo \(`date -d 18-Oct-2027 +' | ||
| - | . / | + | |
| declare -x ServerName=FQHN | declare -x ServerName=FQHN | ||
| - | univention-certificate new -name " | + | declare -x days=$(echo \(`date -d 18-Oct-2027 +' |
| + | </ | ||
| + | Somit sind die Anzahl Tage und der Servername in Variablen gespeichert und können im folgenden benutzt werden. | ||
| + | < | ||
| + | . / | ||
| + | univention-certificate new -name " | ||
| cd / | cd / | ||
| nano openssl.cnf | nano openssl.cnf | ||
| Zeile 25: | Zeile 31: | ||
| openssl req -new -key private.key -config openssl.cnf -out req.pem | openssl req -new -key private.key -config openssl.cnf -out req.pem | ||
| openssl req -in req.pem -noout -text | grep -E " | openssl req -in req.pem -noout -text | grep -E " | ||
| - | univention-certificate renew -name ${ServerName} -days 1825 | + | univention-certificate renew -name ${ServerName} -days $days |
| </ | </ | ||
| + | |||
| + | das ganze kann dann in eine pkcs12 Datei verpackt werden, damit sie z.B. unter Windows importiert werden kann: | ||
| + | < | ||
| + | openssl pkcs12 -export -out / | ||
| + | -in / | ||
| + | -inkey / | ||
| + | -passout pass: | ||
| + | </ | ||
| + | |||
| Zertifikatsfingerabdruck auslesen und auf dem Terminalserver via | Zertifikatsfingerabdruck auslesen und auf dem Terminalserver via | ||
| '' | '' | ||
| Zeile 74: | Zeile 89: | ||
| - create a new cert by using univention-certificate new, use a name you recognize as CS Cert | - create a new cert by using univention-certificate new, use a name you recognize as CS Cert | ||
| - create a special extension file | - create a special extension file | ||
| - | - generate the csr again manually | + | - generate the cert again manually |
| - | - sign it by the ca again by issuing univention-certificate renew | + | - use this cert for signing |
| < | < | ||
| declare -x CertName=CodeSign-YourName | declare -x CertName=CodeSign-YourName | ||
| declare -x ExportPassword=SuperSecurePasswordForP12File | declare -x ExportPassword=SuperSecurePasswordForP12File | ||
| - | + | declare -x days=$(echo \(`date -d 18-Oct-2027 +' | |
| - | grep output_password / | + | |
| - | echo \(`date -d 18-Oct-2027 +' | + | |
| - | declare -x days=`cat days` | + | |
| . / | . / | ||
| Zeile 94: | Zeile 105: | ||
| basicConstraints | basicConstraints | ||
| subjectAltName | subjectAltName | ||
| - | extendedKeyUsage | + | extendedKeyUsage |
| [alt_names] | [alt_names] | ||
| DNS.1 = ${CertName} | DNS.1 = ${CertName} | ||
| " > code_sign_cert.conf | " > code_sign_cert.conf | ||
| + | grep output_password / | ||
| openssl x509 -req -CA ../ | openssl x509 -req -CA ../ | ||