Collections:
Other Resources:
OpenSSL "req -x509 -set_serial" - Certificate Serial Number
Can I sign my own CSR with a given serial number using the OpenSSL "req -x509" command?
✍: FYIcenter.com
Yes, you can sign you own CSR (Certificate Sign Request) with a given serial number
using the OpenSSL "req -x509 -set_serial" command as shown below.
Without the "-set_serial" option, the resulting certificate will have random serial number.
See the example below:
C:\Users\fyicenter>\local\openssl\openssl.exe OpenSSL> req -x509 -in rsa_test.csr -key rsa_test.key -out rsa_test.crt -set_serial 1024 Enter pass phrase for rsa_test.key:fyicenter OpenSSL> x509 -in rsa_test.crt -serial -noout serial=0400
As you can see the given serial number is stored as a binary integer format. In the above example, 0x0400 = 1024.
⇒ OpenSSL "req -x509 -md5" - MD5 Digest for Signing
⇐ OpenSSL "req -x509 -days" - Longer Self-Signed Certificate
2016-11-11, ≈20🔥, 0💬
Popular Posts:
Certificate Summary: Subject: UTN-USERFirst-Hardware Issuer: UTN-USERFirst-Hardware Expiration: 2019...
Certificate summary - Owner: Thawte DV SSL CA, Domain Validated SSL, "Thawte, Inc.", US Issuer: thaw...
Certificate Summary: Subject: QuoVadis Global SSL ICA G3 Issuer: QuoVadis Root CA 2 G3 Expiration: 2...
Certificate summary - Owner: *.spotify.com, COMODO SSL Wildcard, Domain Control Validated Issuer: CO...
Certificate summary - Owner: Go Daddy Secure Certificate Authority - G2, http://certs.godaddy.com /re...