Collections:
Other Resources:
OpenSSL "req -x509 -days" - Longer Self-Signed Certificate
Can I sign my own CSR with a longer expiration date using the OpenSSL "req -x509" command? I want to use this certificate as an internal root CA for 10 years.
✍: FYIcenter.com
Yes, you can sign you own CSR (Certificate Sign Request) with a longer expiration date
using the OpenSSL "req -x509 -days" command as shown below.
Without the "-days" option, the resulting certificate is only valid for 30 days.
See the example below:
C:\Users\fyicenter>\local\openssl\openssl.exe OpenSSL> req -x509 -in rsa_test.csr -key rsa_test.key -out rsa_test.crt -days 3650 Enter pass phrase for rsa_test.key:fyicenter OpenSSL> x509 -in rsa_test.crt -dates -noout notBefore=Aug 21 13:26:41 2016 GMT notAfter=Aug 19 13:26:41 2026 GMT
⇒ OpenSSL "req -x509 -set_serial" - Certificate Serial Number
2016-11-11, ∼5569🔥, 0💬
Popular Posts:
Certificate summary - Owner: *.xda-developers.com, Domain Control Validated - RapidSSL(R), See www.r...
Certificate Summary: Subject: Network Solutions OV Server CA 2 Issuer: USERTrust RSA Certification A...
Certificate Summary: Subject: *.exoclick.com Issuer: Go Daddy Secure Certificate Authority - G2 Expi...
Key Summary: Type: RSA 2048-Bit Public Key Identifier: 8A:74:7F:AF:85:CD:EE:95: CD:3D:9C:D0:E2:46:14:...
Certificate Summary: Subject: QuoVadis Root CA 2 Issuer: QuoVadis Root CA 2 Expiration: 2031-11-24 1...