Benutzer-Werkzeuge

Webseiten-Werkzeuge


lx:ucs:ca

Unterschiede

Hier werden die Unterschiede zwischen zwei Versionen angezeigt.

Link zu dieser Vergleichsansicht

Beide Seiten der vorigen RevisionVorhergehende Überarbeitung
Nächste Überarbeitung
Vorhergehende Überarbeitung
lx:ucs:ca [02.04.2025 18:03] – how to create a CodeSigning Cert Andy Haubenschmidlx:ucs:ca [25.07.2026 22:13] (aktuell) – berechnung der Tage in eine Variable schreiben Andy Haubenschmid
Zeile 10: Zeile 10:
  
 ===== neues Server Zertifikat erstellen ===== ===== neues Server Zertifikat erstellen =====
 +Ausrechnen wie lange das Zertifikat laufen darf, am besten das Ablaufdatum der CA verwenden.
 <code> <code>
 echo \(`date -d 18-Oct-2027 +'%s'` - `date +'%s'`\) /86400 |bc echo \(`date -d 18-Oct-2027 +'%s'` - `date +'%s'`\) /86400 |bc
-. /usr/share/univention-ssl/make-certificates.sh+
 declare -x ServerName=FQHN declare -x ServerName=FQHN
-univention-certificate new -name "${ServerName}" -days 1825+declare -x days=$(echo \(`date -d 18-Oct-2027 +'%s'` - `date +'%s'`\) /86400 |bc) 
 +</code> 
 +Somit sind die Anzahl Tage und der Servername in Variablen gespeichert und können im folgenden benutzt werden. 
 +<code> 
 +. /usr/share/univention-ssl/make-certificates.sh 
 +univention-certificate new -name "${ServerName}" -days $days
 cd /etc/univention/ssl/${ServerName} cd /etc/univention/ssl/${ServerName}
 nano openssl.cnf nano openssl.cnf
Zeile 25: Zeile 31:
 openssl req -new -key private.key -config openssl.cnf -out req.pem openssl req -new -key private.key -config openssl.cnf -out req.pem
 openssl req -in req.pem -noout -text | grep -E "(Subject Alternative Name|DNS)" openssl req -in req.pem -noout -text | grep -E "(Subject Alternative Name|DNS)"
-univention-certificate renew -name ${ServerName} -days 1825+univention-certificate renew -name ${ServerName} -days $days
 </code> </code>
 +
 +das ganze kann dann in eine pkcs12 Datei verpackt werden, damit sie z.B. unter Windows importiert werden kann:
 +<code>
 +openssl pkcs12 -export -out /root/${ServerName}.p12 \
 +-in /etc/univention/ssl/${ServerName}/cert.pem \
 +-inkey /etc/univention/ssl/${ServerName}/private.key \
 +-passout pass:EinSehrSicheresPasswort
 +</code>
 +
 Zertifikatsfingerabdruck auslesen und auf dem Terminalserver via  Zertifikatsfingerabdruck auslesen und auf dem Terminalserver via 
 ''wmic /namespace:rootcimv2TerminalServices PATH Win32_TSGeneralSetting Set SSLCertificateSHA1Hash="Fingerabdruck"'' das Zertifikat für RDP verwenden. ''wmic /namespace:rootcimv2TerminalServices PATH Win32_TSGeneralSetting Set SSLCertificateSHA1Hash="Fingerabdruck"'' das Zertifikat für RDP verwenden.
Zeile 74: Zeile 89:
   - create a new cert by using univention-certificate new, use a name you recognize as CS Cert   - create a new cert by using univention-certificate new, use a name you recognize as CS Cert
   - create a special extension file   - create a special extension file
-  - generate the csr again manually +  - generate the cert again manually by the CA with the extension 
-  - sign it by the ca again by issuing univention-certificate renew +  - use this cert for signing
  
 <code> <code>
 declare -x CertName=CodeSign-YourName declare -x CertName=CodeSign-YourName
 declare -x ExportPassword=SuperSecurePasswordForP12File declare -x ExportPassword=SuperSecurePasswordForP12File
- +declare -x days=$(echo \(`date -d 18-Oct-2027 +'%s'` - `date +'%s'`\) /86400 |bc)
-grep output_password /etc/univention/ssl/openssl.cnf +
-echo \(`date -d 18-Oct-2027 +'%s'` - `date +'%s'`\) /86400 |bc > days +
-declare -x days=`cat days`+
  
 . /usr/share/univention-ssl/make-certificates.sh . /usr/share/univention-ssl/make-certificates.sh
Zeile 94: Zeile 105:
 basicConstraints       = CA:FALSE basicConstraints       = CA:FALSE
 subjectAltName         = @alt_names subjectAltName         = @alt_names
-extendedKeyUsage       = codeSigning,1.3.6.1.5.5.7.3.3 +extendedKeyUsage       = codeSigning
 [alt_names] [alt_names]
 DNS.1 = ${CertName} DNS.1 = ${CertName}
 " > code_sign_cert.conf " > code_sign_cert.conf
  
 +grep output_password /etc/univention/ssl/openssl.cnf
 openssl x509 -req -CA ../ucsCA/CAcert.pem -CAkey ../ucsCA/private/CAkey.pem -in req.pem -out cert.pem -days ${days} -CAcreateserial -extfile code_sign_cert.conf  openssl x509 -req -CA ../ucsCA/CAcert.pem -CAkey ../ucsCA/private/CAkey.pem -in req.pem -out cert.pem -days ${days} -CAcreateserial -extfile code_sign_cert.conf 
  
lx/ucs/ca.1743616989.txt.gz · Zuletzt geändert: von Andy Haubenschmid