2016-08-03 23:29:18 +02:00
2016-08-04 17:54:02 +02:00
2019-02-03 15:36:37 +05:30
2016-08-08 01:55:42 +02:00
2016-08-03 23:29:18 +02:00
# CN = Common Name
# OU = Organization Unit
# O = Organization Name
# L = Locality Name
# ST = State Name
# C = Country (2-letter Country Code)
# E = Email
DNAME_CA='CN=Baeldung CA,OU=baeldung.com,O=Baeldung,L=SomeCity,ST=SomeState,C=CC'
# For server certificates, the Common Name (CN) must be the hostname
2016-08-04 17:54:02 +02:00
2016-08-03 23:29:18 +02:00
all: clean create-keystore add-host create-truststore add-client
# Generate a certificate authority (CA)
2018-08-01 20:14:08 -03:00
keytool -genkey -alias ca -ext san=dns:localhost,ip: -ext BC=ca:true \
2016-08-03 23:29:18 +02:00
-keyalg RSA -keysize 4096 -sigalg SHA512withRSA -keypass $(PASSWORD) \
-validity 3650 -dname $(DNAME_CA) \
-keystore $(KEYSTORE) -storepass $(PASSWORD)
# Generate a host certificate
2018-08-01 20:14:08 -03:00
keytool -genkey -alias $(HOSTNAME) -ext san=dns:localhost,ip: \
2016-08-03 23:29:18 +02:00
-keyalg RSA -keysize 4096 -sigalg SHA512withRSA -keypass $(PASSWORD) \
-validity 3650 -dname $(DNAME_HOST) \
-keystore $(KEYSTORE) -storepass $(PASSWORD)
# Generate a host certificate signing request
2018-08-01 20:14:08 -03:00
keytool -certreq -alias $(HOSTNAME) -ext san=dns:localhost,ip: -ext BC=ca:true \
2016-08-03 23:29:18 +02:00
-keyalg RSA -keysize 4096 -sigalg SHA512withRSA \
-validity 3650 -file "$(HOSTNAME).csr" \
-keystore $(KEYSTORE) -storepass $(PASSWORD)
# Generate signed certificate with the certificate authority
2018-08-01 20:14:08 -03:00
keytool -gencert -alias ca -ext san=dns:localhost,ip: \
2016-08-03 23:29:18 +02:00
-validity 3650 -sigalg SHA512withRSA \
-infile "$(HOSTNAME).csr" -outfile "$(HOSTNAME).crt" -rfc \
-keystore $(KEYSTORE) -storepass $(PASSWORD)
# Import signed certificate into the keystore
2018-08-01 20:14:08 -03:00
keytool -import -trustcacerts -alias $(HOSTNAME) -ext san=dns:localhost,ip: \
2016-08-03 23:29:18 +02:00
-file "$(HOSTNAME).crt" \
-keystore $(KEYSTORE) -storepass $(PASSWORD)
2016-08-04 17:54:02 +02:00
# Export certificate authority
2018-08-01 20:14:08 -03:00
keytool -export -alias ca -ext san=dns:localhost,ip: -file ca.crt -rfc \
2016-08-03 23:29:18 +02:00
-keystore $(KEYSTORE) -storepass $(PASSWORD)
2016-08-04 17:54:02 +02:00
create-truststore: export-authority
# Import certificate authority into a new truststore
2018-08-01 20:14:08 -03:00
keytool -import -trustcacerts -noprompt -alias ca -ext san=dns:localhost,ip: -file ca.crt \
2016-08-03 23:29:18 +02:00
-keystore $(TRUSTSTORE) -storepass $(PASSWORD)
# Generate client certificate
2019-02-03 15:36:37 +05:30
keytool -genkey -alias $(CLIENT_PRIVATE_KEY) -ext san=dns:localhost,ip: \
2016-08-03 23:29:18 +02:00
-keyalg RSA -keysize 4096 -sigalg SHA512withRSA -keypass $(PASSWORD) \
2016-08-04 17:54:02 +02:00
-validity 3650 -dname $(DNAME_CLIENT) \
2016-08-03 23:29:18 +02:00
-keystore $(TRUSTSTORE) -storepass $(PASSWORD)
# Generate a host certificate signing request
2019-02-03 15:36:37 +05:30
keytool -certreq -alias $(CLIENT_PRIVATE_KEY) -ext san=dns:localhost,ip: -ext BC=ca:true \
2016-08-03 23:29:18 +02:00
-keyalg RSA -keysize 4096 -sigalg SHA512withRSA \
-validity 3650 -file "$(CLIENTNAME).csr" \
-keystore $(TRUSTSTORE) -storepass $(PASSWORD)
# Generate signed certificate with the certificate authority
2018-08-01 20:14:08 -03:00
keytool -gencert -alias ca -ext san=dns:localhost,ip: \
2016-08-03 23:29:18 +02:00
-validity 3650 -sigalg SHA512withRSA \
-infile "$(CLIENTNAME).csr" -outfile "$(CLIENTNAME).crt" -rfc \
-keystore $(KEYSTORE) -storepass $(PASSWORD)
# Import signed certificate into the truststore
2018-08-01 20:14:08 -03:00
keytool -import -trustcacerts -alias $(CLIENTNAME) -ext san=dns:localhost,ip: \
2016-08-03 23:29:18 +02:00
-file "$(CLIENTNAME).crt" \
-keystore $(TRUSTSTORE) -storepass $(PASSWORD)
2016-08-08 01:55:42 +02:00
# Export private certificate for importing into a browser
2019-02-03 15:36:37 +05:30
keytool -importkeystore -srcalias $(CLIENT_PRIVATE_KEY) -ext san=dns:localhost,ip: \
2016-08-08 01:55:42 +02:00
-srckeystore $(TRUSTSTORE) -srcstorepass $(PASSWORD) \
-destkeystore "$(CLIENTNAME).p12" -deststorepass $(PASSWORD) \
-deststoretype PKCS12
2019-02-03 15:36:37 +05:30
# Delete client private key as truststore should not contain any private keys
keytool -delete -alias $(CLIENT_PRIVATE_KEY) \
-keystore $(TRUSTSTORE) -storepass $(PASSWORD)
2016-08-03 23:29:18 +02:00
2016-08-04 17:54:02 +02:00
# Remove generated artifacts
2018-07-17 22:46:32 +03:00
find . \( -name "$(CLIENTNAME)*" -o -name "$(HOSTNAME)*" -o -name "$(KEYSTORE)" -o -name "$(TRUSTSTORE)" -o -name ca.crt \) -type f -exec rm -f {} \;