This is an old revision of the document!
openssl req -config ./openssl.cnf -newkey rsa:2048 -nodes -keyform PEM -keyout cakey.pem -x509 -days 3650 -extensions certauth -outform PEM -out cacert.pem
generovani klice serveru
openssl genrsa -out server.key 2048
generovani zadosti o certifikat serveru
openssl req -config ./openssl.cnf -new -key server.key -out server.req
generovani certifikatu serveru
openssl x509 -req -in server.req -CA cacert.pem -CAkey cakey.pem -set_serial 100 -extfile openssl.cnf -extensions server -days 365 -outform PEM -out server.pem
generovani klice clienta
openssl genrsa -out client.key 2048
generovani zadosti o certifikat clienta
openssl req -config ./openssl.cnf -new -key client.key -out client.req
generovani certifikatu clienta
openssl x509 -req -in client.req -CA cacert.pem -CAkey cakey.pem -set_serial 101 -extfile openssl.cnf -extensions client -days 365 -outform PEM -out client.pem
klientsky certifikat s heslem ve formatu pkcs12
openssl pkcs12 -export -in client/client_test.pem -inkey client/client_test.key -out client/client_test.p12