SSL / TLS certificates generation
- SSL / TLS certificates generation
- Generate SSL certificate
- SSL certificate generation
- Generate TLS certificate
- TLS certificate generation
We have a server and a client. Connecting via SSL/TLS protocols not only encrypts the transmitted data but also ensures that the client is confident they are connecting to the intended server.
To achieve this, the server must complete an authentication procedure, or “show its passport”. This process is known as One-Way SSL.
In some cases, both the server and client exchange passports. This mechanism is known as Two-Way SSL.
Obtaining Certificates
There are two options for obtaining certificates:
Self-Generated Certificates
- Free and suitable if you can install a keystore (certificate store) and truststore (trusted certificates store) on both the server and client.
Certificates from a Renowned CA
- Purchased from a recognized Certification Authority (CA), which is trusted by major software vendors.
- Alternatively, you can create your own CA, similar to self-generation, where the truststore is customized.
Certificates must be signed by root certificates. For testing environments, self-signed certificates (where they serve as their own root) may be used, while production uses a root CA certificate.
Steps for generating or purchasing certificates involve signing them with the CA’s root certificate.
Trusting Certificates
For the server or client to trust the certificate:
- Both must trust the CA that issued the certificate.
- A standard database of trusted root-CA certificates exists, such as the
cacertsfile in Java.
To install a purchased or custom-generated certificate:
- Specify the keystore containing the certificate (e.g., JKS, keystore file).
- If self-generated using your own CA, also specify a truststore with the root CA certificate.
One-Way SSL
Steps to Create a Certificate Store (Keystore)
1. Create the keystore
keytool -genkey -alias bmc -keyalg RSA -keystore server_keystore.jks -keysize 2048
2. Generate a new CA certificate and its key
openssl req -new -x509 -keyout server-ca-key -out server_ca_cert
3. Create a Certificate Signing Request (CSR)
keytool -keystore server_keystore.jks -alias bmc -certreq -file server_cert_file
4. Create a signed certificate
openssl x509 -req -CA server_ca_cert -CAkey server-ca-key -in server_cert_file -out server_cert_signed -days 365 -CAcreateserial -passin pass: qwe123
5. Import the CA certificate into the keystore
keytool -keystore server_keystore.jks -alias CARoot -import -file server_ca_cert
6. Import the signed certificate into the keystore
keytool -keystore server_keystore.jks -alias bmc -import -file server_cert_signed
7. Create a client trust store and import the root CA certificate
keytool -keystore client_truststore.jks -alias bmc -import -file server_ca_cert
At certain stages, you’ll need to provide passwords. To avoid confusion, use the same password (e.g., qwe123) throughout. Also, ensure the CN (Common Name) field matches the hostname where the certificate will be used.
Output Files
server_keystore.jksclient_truststore.jks
Two-Way SSL
To enable Two-Way SSL:
- Generate certificates for each side (server and client) as described for One-Way SSL.
- Repeat the process for the client, mirroring the commands but using different file names.
Here are the commands for the client:
1. Create the client keystore
keytool -genkey -alias bmc -keyalg RSA -keystore client_keystore.jks -keysize 2048
2. Generate a new CA certificate and its key (client-side)
openssl req -new -x509 -keyout client-ca-key -out client_ca_cert
3. Create a Certificate Signing Request (CSR)
keytool -keystore client_keystore.jks -alias bmc -certreq -file client_cert_file
4. Create a signed certificate
openssl x509 -req -CA client_ca_cert -CAkey client-ca-key -in client_cert_file -out client_cert_signed -days 365 -CAcreateserial -passin pass: qwe123
5. Import the CA certificate into the client keystore
keytool -keystore client_keystore.jks -alias CARoot -import -file client_ca_cert
6. Import the signed certificate into the client keystore
keytool -keystore client_keystore.jks -alias bmc -import -file client_cert_signed
7. Create a server trust store and import the client root CA certificate
keytool -keystore server_truststore.jks -alias bmc -import -file client_ca_cert
Output Files
server_keystore.jksserver_truststore.jksclient_keystore.jksclient_truststore.jks
Result Summary
From the commands above, you will have four key files:
server_keystore.jksserver_truststore.jksclient_keystore.jksclient_truststore.jks
These files enable secure communication via One-Way SSL or Two-Way SSL.