CA

共 2 篇文章。

India NIC签发未经授权的 Google SSL证书事件

• Security

详情参见 Google Online Security Blog。

说两个我认为比较有意思的事情:

第一个是 Google 并没有公布作为证据的证书。由于证书是以 CA 的私钥签署,因此这类未经授权的证书本身就可以作为证据。但是,Google这样做(不公布证书)意味着签发者不得不销毁全部签发的证书,而不仅仅是被公布的那些。

阅读全文… ( 本文约 362 字,阅读大致需要 1 分钟 )

作弊条:SSL/TLS证书的生成

• Cheatsheets

防止下次再求助于archive。这是我用来给自己的SMTP/POP3/HTTPS服务器生成证书的全部命令行,仅限服务器证书部分。

cd /usr/local/CA
openssl req -nodes -new -x509 -keyout mykey.pem -out myreq.pem \
-days 365 -config openssl.cnf
openssl x509 -x509toreq -in myreq.pem -signkey mykey.pem -out tmp.pem
openssl ca -config openssl.cnf -policy policy_anything \
-out mycert.pem -infiles tmp.pem
rm -f tmp.pem

参与评论