[CentOS] Creating your own CA and SSL certificates

Robert Moskowitz rgm at htt-consult.com
Tue Aug 28 13:03:12 UTC 2007



Brian Mathis wrote:
> I've been looking all over (google, wiki, manuals) for docs, and I
> can't find any mention of how to set up a CA or certificates
> *specifically for centos 5 / upstream 5*.  There are plenty of generic
> guides on using openssl for this sort of thing, but I'd like to play
> nice within the standard structure of this system.
>   
Consider getting TinyCA2 from rpmforge.

It more than does the job. In fact you can create your own root cert and 
any number of server certs. then just the one root cert installed in 
browsers will take care of all your TLS needs.
> I've found the /etc/pki directory, but can't find much information
> about it.  I reviewed the openssl.cnf file, and it looks like it's not
> completely set up, as many directories it references do not exist on
> the system.
>
> What I'm looking to do is set up my own CA, then make some
> certificates for use with SSL, and sign them with the CA.  This will
> be used for internal purposes.
>
> Any pointers to guides or information would be appreciated.
> Thanks.
> _______________________________________________
> CentOS mailing list
> CentOS at centos.org
> http://lists.centos.org/mailman/listinfo/centos
>
>   



More information about the CentOS mailing list