certdemo.sh 2.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243
  1. #!/bin/bash -x
  2. set -e
  3. gmssl sm2keygen -pass 1234 -out rootcakey.pem
  4. gmssl certgen -C CN -ST Beijing -L Haidian -O PKU -OU CS -CN ROOTCA -days 3650 \
  5. -key rootcakey.pem -pass 1234 \
  6. -out rootcacert.pem \
  7. -ca -path_len_constraint 6 \
  8. -key_usage keyCertSign -key_usage cRLSign \
  9. -crl_http_uri http://pku.edu.cn/ca.crl -ca_issuers_uri http://pku.edu.cn/ca.crt -ocsp_uri http://ocsp.pku.edu.cn
  10. gmssl certparse -in rootcacert.pem
  11. gmssl sm2keygen -pass 1234 -out cakey.pem
  12. gmssl reqgen -C CN -ST Beijing -L Haidian -O PKU -OU CS -CN "Sub CA" -key cakey.pem -pass 1234 -out careq.pem
  13. gmssl reqsign -in careq.pem -days 365 -key_usage keyCertSign -path_len_constraint 0 -cacert rootcacert.pem -key rootcakey.pem -pass 1234 -out cacert.pem \
  14. -crl_http_uri http://pku.edu.cn/ca.crl -ca_issuers_uri http://pku.edu.cn/ca.crt -ocsp_uri http://ocsp.pku.edu.cn
  15. gmssl certparse -in cacert.pem
  16. gmssl sm2keygen -pass 1234 -out signkey.pem
  17. gmssl reqgen -C CN -ST Beijing -L Haidian -O PKU -OU CS -CN localhost -key signkey.pem -pass 1234 -out signreq.pem
  18. gmssl reqsign -in signreq.pem -days 365 -key_usage digitalSignature -cacert cacert.pem -key cakey.pem -pass 1234 -out signcert.pem \
  19. -crl_http_uri http://github.com/guanzhi/GmSSL/raw/master/demos/certs/SubCA-1.crl
  20. gmssl certparse -in signcert.pem
  21. gmssl sm2keygen -pass 1234 -out enckey.pem
  22. gmssl reqgen -C CN -ST Beijing -L Haidian -O PKU -OU CS -CN localhost -key enckey.pem -pass 1234 -out encreq.pem
  23. gmssl reqsign -in encreq.pem -days 365 -key_usage keyEncipherment -cacert cacert.pem -key cakey.pem -pass 1234 -out enccert.pem \
  24. -crl_http_uri http://github.com/guanzhi/GmSSL/raw/master/demos/certs/SubCA-1.crl
  25. gmssl certparse -in enccert.pem
  26. cat signcert.pem > certs.pem
  27. cat cacert.pem >> certs.pem
  28. gmssl certverify -in certs.pem -cacert rootcacert.pem #-check_crl
  29. cat signcert.pem > dbl_certs.pem
  30. cat enccert.pem >> dbl_certs.pem
  31. cat cacert.pem >> dbl_certs.pem
  32. gmssl certverify -double_certs -in dbl_certs.pem -cacert rootcacert.pem #-check_crl
  33. echo ok