From: Richard Levitte Date: Thu, 3 Apr 2003 22:12:48 +0000 (+0000) Subject: It's recommended to use req rather than x509 to create self-signed certificates X-Git-Tag: BEN_FIPS_TEST_1~38^2~169 X-Git-Url: https://git.openssl.org/?p=openssl.git;a=commitdiff_plain;h=8152d887992c8f15fcf63c7da48c5d8805f1b3b2 It's recommended to use req rather than x509 to create self-signed certificates --- diff --git a/doc/HOWTO/certificates.txt b/doc/HOWTO/certificates.txt index d7e16c1da1..d3a62545ad 100644 --- a/doc/HOWTO/certificates.txt +++ b/doc/HOWTO/certificates.txt @@ -71,13 +71,11 @@ received. If you don't want to deal with another certificate authority, or just want to create a test certificate for yourself, or are setting up a certificate authority of your own, you may want to make the requested -certificate a self-signed one. If you have created a certificate -request as shown above, you can sign it using the 'openssl x509' -command, for example like this (to create a self-signed CA -certificate): +certificate a self-signed one. This is similar to creating a +certificate request, but creates a certificate instead of a +certificate request (1095 is 3 years): - openssl x509 -req -in cert.csr -extfile openssl.cnf -extensions v3_ca \ - -signkey privkey.pem -out cacert.pem -trustout + openssl req -new -x509 -key privkey.pem -out cacert.pem -days 1095 5. What to do with the certificate