1.[root@BlackGhostssl]#./CA.sh-newca//创建主证书
2.CAcertificatefilename(orentertocreate)
3.
4.MakingCAcertificate...
5.Generatinga1024bitRSAprivatekey
6.............++++++
7.......++++++
8.writingnewprivatekeyto./demoCA/private/./cakey.pem
9.EnterPEMpassphrase:
10.Verifying-EnterPEMpassphrase:
11.Verifyfailure
12.EnterPEMpassphrase:
13.Verifying-EnterPEMpassphrase:
14.-----
15.Youareabouttobeaskedtoenterinformationthatwillbeincorporated
16.intoyourcertificaterequest.
17.WhatyouareabouttoenteriswhatiscalledaDistinguishedNameoraDN.
18.Therearequiteafewfieldsbutyoucanleavesomeblank
19.Forsomefieldstherewillbeadefaultvalue,
20.Ifyouenter.,thefieldwillbeleftblank.
21.-----
22.CountryName(2lettercode)[AU]:cn
23.StateorProvinceName(fullname)[Some-State]:cn
24.LocalityName(eg,city)[]:cn
25.OrganizationName(eg,company)[InternetWidgitsPtyLtd]:cn
26.OrganizationalUnitName(eg,section)[]:cn
27.CommonName(eg,YOURname)[]:localhost
28.EmailAddress[]:xtaying@gmail.com
29.
30.Pleaseenterthefollowingextraattributes
31.tobesentwithyourcertificaterequest
32.Achallengepassword[]:******************
33.Anoptionalcompanyname[]:
34.Usingconfigurationfrom/etc/ssl/openssl.cnf
35.Enterpassphrasefor./demoCA/private/./cakey.pem://填的是下面的PEM暗码
36.Checkthattherequestmatchesthesignature
37.Signatureok
38.CertificateDetails:
39.SerialNumber:
40.89:11:9f:a6:ca:03:63:ab
41.Validity
42.NotBefore:Aug712:35:282010GMT
43.NotAfter:Aug612:35:282013GMT
44.Subject:
45.countryName=cn
46.stateOrProvinceName=cn
47.organizationName=cn
48.organizationalUnitName=cn
49.commonName=localhost
50.emailAddress=xtaying@gmail.com
51.X509v3extensions:
52.X509v3SubjectKeyIdentifier:
53.26:09:F3:D5:26:13:00:1F:3E:CC:86:1D:E4:EE:37:06:65:15:4E:76
54.X509v3AuthorityKeyIdentifier:
55.keyid:26:09:F3:D5:26:13:00:1F:3E:CC:86:1D:E4:EE:37:06:65:15:4E:76
56.DirName:/C=cn/ST=cn/O=cn/OU=cn/CN=localhost/emailAddress=xtaying@gmail.com
57.serial:89:11:9F:A6:CA:03:63:AB
58.
59.X509v3BasicConstraints:
60.CA:TRUE
61.CertificateistobecertifieduntilAug612:35:282013GMT(1095days)
62.
63.Writeoutdatabasewith1newentries
64.DataBaseUpdated