ºìÁªLinuxÃÅ»§
Linux°ïÖú

´´½¨opensslÖ¤ÊéºÍCAµÄ×î¼òµ¥µÄ·½·¨

·¢²¼Ê±¼ä:2008-08-09 00:52:52À´Ô´:ºìÁª×÷Õß:sloepx
½ñÌì´ò¿ªthunderbirdÁ¬½Óµ½VPSÉϵÄdovecot imapsÓʼþ·þÎñÆ÷£¬thunderbird±¨¸æËµsslÖ¤Êé¹ýÆÚÁË¡£Ô­À´ÊÇdovecot°²×°Ê±ºò×Ô´øµÄÖ¤ÊéÓÐЧÆÚÌ«¶Ì£¬½ñÌìµ½ÆÚÁË£¬¸Ã¸üÐÂÖ¤ÊéÁË¡£

ÍøÂçÉÏËÑË÷µ½µÄ´ó²¿·Ö·½·¨¶¼ÊÇÓÃopensslÃüÁîÀ´´´½¨caºÍÖ¤Ê飬ÕâÖÖ·½·¨±È½ÏÂé·³£¬ÈÝÒ׳ö´í¡£

ÎÒÓÃcerttool¹¤¾ßÓÖÖØÐ´´½¨ÁËÒ»¸öcaºÍÒ»¸ö×ÔÈÏÖ¤µÄopensslÖ¤Êé¡£¹ý³Ì¼Ç¼ÈçÏ£º

certtoolÕâ¸ö¹¤¾ß°üº¬ÔÚgnutlsÕâ¸ö°üÀïÃæ£¬Ê×ÏÈÒªÔÚVPSÉϰ²×°Õâ¸ö°ü£¬ÔÚDebian/Ubuntu VPSÉÏÔËÐÐ

apt-get install gnutls-bin gnutls-doc

ÔÚCentOS VPSÉÏÐèÒªÔËÐУº

yum install -y gnutls-utils

´´½¨ca.infoÎļþ£¬ÄÚÈÝÈçÏ£º

cn = rashostcacert_signing_keyexpiration_days = 3650

´´½¨CA£º

certtool --generate-privkey > ca.keycerttool --generate-self-signed --load-privkey ca.key --template ca.info --outfile ca.certcerttool -i --infile ca.cert

´´½¨rashost.com.infoÎļþ£¬ÄÚÈÝÈçÏ£º

organization = rashost Inc.cn = rashost.comtls_www_serverencryption_keysigning_keyexpiration_days = 3650

È»ºó´´½¨Ö¤Ê飺

certtool --generate-privkey > rashost.com.keycerttool --generate-certificate --load-privkey rashost.com.key --load-ca-certificate ca.cert --load-ca-privkey ca.key --template rashost.com.info --outfile rashost.com.certcerttool -i --infile rashost.com.cert

rashost.com.certÊÇÖ¤ÊéÎļþ£¬rashost.com.keyÊÇÃÜÔ¿Îļþ£¬ÔÚdovecotµÄÅäÖÃÎļþÀïʹÓÃÕâÁ½¸öÎļþ¾Í¿ÉÒÔÁË¡£

µØÖ· http://vpsblog.rashost.com/
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 2 ÌõÆÀÂÛ

  1. blue_eagle ÓÚ 2010-10-18 23:10:16·¢±í:

    ѧϰÁË¡£¶¥Ò»Ï¡£×î½üÔÚÑо¿SSL¡£Ï£ÍûÄÜ»ñÈ¡¸ü¶àCAÏà¹ØµÄ֪ʶ¡£

  2. wangyoubang ÓÚ 2009-08-02 09:22:34·¢±í:

    ¶¥Ò»¸ö ѧϰÁË