SSL / TLS certificates generation


What's inside this article ⌄
  • SSL / TLS certificates generation
  • Generate SSL certificate
  • SSL certificate generation
  • Generate TLS certificate
  • TLS certificate generation

We have a server and a client. Connecting via SSL/TLS protocols not only encrypts the transmitted data but also ensures that the client is confident they are connecting to the intended server.

To achieve this, the server must complete an authentication procedure, or “show its passport”. This process is known as One-Way SSL.

In some cases, both the server and client exchange passports. This mechanism is known as Two-Way SSL.


Obtaining Certificates

There are two options for obtaining certificates:

  1. Self-Generated Certificates

    • Free and suitable if you can install a keystore (certificate store) and truststore (trusted certificates store) on both the server and client.
  2. Certificates from a Renowned CA

    • Purchased from a recognized Certification Authority (CA), which is trusted by major software vendors.
    • Alternatively, you can create your own CA, similar to self-generation, where the truststore is customized.

Certificates must be signed by root certificates. For testing environments, self-signed certificates (where they serve as their own root) may be used, while production uses a root CA certificate.

Steps for generating or purchasing certificates involve signing them with the CA’s root certificate.


Trusting Certificates

For the server or client to trust the certificate:

  • Both must trust the CA that issued the certificate.
  • A standard database of trusted root-CA certificates exists, such as the cacerts file in Java.

To install a purchased or custom-generated certificate:

  1. Specify the keystore containing the certificate (e.g., JKS, keystore file).
  2. If self-generated using your own CA, also specify a truststore with the root CA certificate.

One-Way SSL

Steps to Create a Certificate Store (Keystore)

1. Create the keystore

keytool -genkey -alias bmc -keyalg RSA -keystore server_keystore.jks -keysize 2048

2. Generate a new CA certificate and its key

openssl req -new -x509 -keyout server-ca-key -out server_ca_cert

3. Create a Certificate Signing Request (CSR)

keytool -keystore server_keystore.jks -alias bmc -certreq -file server_cert_file

4. Create a signed certificate

openssl x509 -req -CA server_ca_cert -CAkey server-ca-key -in server_cert_file -out server_cert_signed -days 365 -CAcreateserial -passin pass: qwe123

5. Import the CA certificate into the keystore

keytool -keystore server_keystore.jks -alias CARoot -import -file server_ca_cert

6. Import the signed certificate into the keystore

keytool -keystore server_keystore.jks -alias bmc -import -file server_cert_signed

7. Create a client trust store and import the root CA certificate

keytool -keystore client_truststore.jks -alias bmc -import -file server_ca_cert

At certain stages, you’ll need to provide passwords. To avoid confusion, use the same password (e.g., qwe123) throughout. Also, ensure the CN (Common Name) field matches the hostname where the certificate will be used.

Output Files

  • server_keystore.jks
  • client_truststore.jks

Two-Way SSL

To enable Two-Way SSL:

  • Generate certificates for each side (server and client) as described for One-Way SSL.
  • Repeat the process for the client, mirroring the commands but using different file names.

Here are the commands for the client:

1. Create the client keystore

keytool -genkey -alias bmc -keyalg RSA -keystore client_keystore.jks -keysize 2048

2. Generate a new CA certificate and its key (client-side)

openssl req -new -x509 -keyout client-ca-key -out client_ca_cert

3. Create a Certificate Signing Request (CSR)

keytool -keystore client_keystore.jks -alias bmc -certreq -file client_cert_file

4. Create a signed certificate

openssl x509 -req -CA client_ca_cert -CAkey client-ca-key -in client_cert_file -out client_cert_signed -days 365 -CAcreateserial -passin pass: qwe123

5. Import the CA certificate into the client keystore

keytool -keystore client_keystore.jks -alias CARoot -import -file client_ca_cert

6. Import the signed certificate into the client keystore

keytool -keystore client_keystore.jks -alias bmc -import -file client_cert_signed

7. Create a server trust store and import the client root CA certificate

keytool -keystore server_truststore.jks -alias bmc -import -file client_ca_cert

Output Files

  • server_keystore.jks
  • server_truststore.jks
  • client_keystore.jks
  • client_truststore.jks

Result Summary

From the commands above, you will have four key files:

  1. server_keystore.jks
  2. server_truststore.jks
  3. client_keystore.jks
  4. client_truststore.jks

These files enable secure communication via One-Way SSL or Two-Way SSL.