Difference between revisions of "SSL: Generate SSL Certificate Request"
Jump to navigation
Jump to search
Onnowpurbo (talk | contribs) (Created page with "Sumber: https://vitux.com/how-to-generate-a-certificate-signing-request-csr-on-ubuntu/ ==Referensi== * https://vitux.com/how-to-generate-a-certificate-signing-request-c...") |
Onnowpurbo (talk | contribs) |
||
(3 intermediate revisions by the same user not shown) | |||
Line 1: | Line 1: | ||
Sumber: https://vitux.com/how-to-generate-a-certificate-signing-request-csr-on-ubuntu/ | Sumber: https://vitux.com/how-to-generate-a-certificate-signing-request-csr-on-ubuntu/ | ||
+ | ==Step 1: Generate a private key== | ||
+ | sudo openssl genrsa –out domain.key 2048 | ||
+ | |||
+ | ==Step 2: Generate the CSR== | ||
+ | |||
+ | sudo openssl req –new –key domain.key –out domain.csr | ||
+ | |||
+ | ==Alternative Method of generating a CSR== | ||
+ | |||
+ | Generate Certificate Signing Request (CSR) dan Private Key sekaligus | ||
+ | |||
+ | sudo openssl req -new -newkey rsa:2048 -nodes -keyout domain.key -out domain.csr | ||
+ | |||
+ | sudo openssl req -new -newkey rsa:2048 -nodes -keyout lms.onnocenter.or.id.key -out lms.onnocenter.or.id.csr | ||
+ | sudo openssl req -new -newkey rsa:2048 -nodes -keyout onnocenter.or.id.key -out onnocenter.or.id.csr | ||
+ | |||
+ | |||
+ | ==CNAME DNS Authentication== | ||
+ | |||
+ | Biasanya penyedia SSL akan meminta kita untuk mengauthentikasi domain kita menggunakan CNAME. Kita perlu menambahkan entry CNAME pada DNS sesuai dengan perintah dari penyedia layanan SSL, misalnya, | ||
+ | |||
+ | _e1a29010855492a.onnocenter.or.id. IN CNAME 2705001641008713.sectigo.com. | ||
+ | _e1a29010855492a.onnocenter.or.id. IN CNAME 2705001641008713.comodoca.com. | ||
Latest revision as of 05:48, 3 January 2022
Sumber: https://vitux.com/how-to-generate-a-certificate-signing-request-csr-on-ubuntu/
Step 1: Generate a private key
sudo openssl genrsa –out domain.key 2048
Step 2: Generate the CSR
sudo openssl req –new –key domain.key –out domain.csr
Alternative Method of generating a CSR
Generate Certificate Signing Request (CSR) dan Private Key sekaligus
sudo openssl req -new -newkey rsa:2048 -nodes -keyout domain.key -out domain.csr
sudo openssl req -new -newkey rsa:2048 -nodes -keyout lms.onnocenter.or.id.key -out lms.onnocenter.or.id.csr sudo openssl req -new -newkey rsa:2048 -nodes -keyout onnocenter.or.id.key -out onnocenter.or.id.csr
CNAME DNS Authentication
Biasanya penyedia SSL akan meminta kita untuk mengauthentikasi domain kita menggunakan CNAME. Kita perlu menambahkan entry CNAME pada DNS sesuai dengan perintah dari penyedia layanan SSL, misalnya,
_e1a29010855492a.onnocenter.or.id. IN CNAME 2705001641008713.sectigo.com. _e1a29010855492a.onnocenter.or.id. IN CNAME 2705001641008713.comodoca.com.