過去のメモ類です
合わせてsystemd用起動ファイル[Unit]Description=The nginx HTTP and reverse proxy serverAfter=syslog.target network.target remote-fs.target nss-lookup.target [Service]Type=forkingPIDFile=/var/run/nginx.pidExecStartPre=/usr/sbin/nginx -tExecStart=/usr/sbin/nginxExecReload=/bin/kill -s HUP $MAINPIDExecStop=/bin/kill -s QUIT $MAINPIDPrivateTmp=true [Install]WantedBy=multi-user.target
おまけ(修正)ECDSA 521bit&SHA512の鍵とCRTを作る例# KEYopenssl ecparam -genkey -name secp521r1 -out server.key# CSRopenssl req -new -days 3650 -sha512 -key server.key -out server.csr \-subj "/C=JP/ST=---/L=---/O=kickitout.net/OU=sieben/CN=sieben.kickitout.net/emailAddress=webmaster@kickitout.net"# CRTopenssl x509 -req -sha512 -days 3650 -in server.csr -signkey server.key -out server.crt# KEY checkopenssl ecparam -check -noout -in server.key# CSR checkopenssl req -verify -noout -in server.csr# CRT subjectopenssl x509 -noout -subject -in server.crt
chrome42だとsecp521r1が駄目みたいscp384r1なら行けるopenssl ecparam -genkey -name secp384r1 -genkey -out server.key
コメントを投稿
3 件のコメント :
合わせてsystemd用起動ファイル
[Unit]
Description=The nginx HTTP and reverse proxy server
After=syslog.target network.target remote-fs.target nss-lookup.target
[Service]
Type=forking
PIDFile=/var/run/nginx.pid
ExecStartPre=/usr/sbin/nginx -t
ExecStart=/usr/sbin/nginx
ExecReload=/bin/kill -s HUP $MAINPID
ExecStop=/bin/kill -s QUIT $MAINPID
PrivateTmp=true
[Install]
WantedBy=multi-user.target
おまけ(修正)
ECDSA 521bit&SHA512の鍵とCRTを作る例
# KEY
openssl ecparam -genkey -name secp521r1 -out server.key
# CSR
openssl req -new -days 3650 -sha512 -key server.key -out server.csr \
-subj "/C=JP/ST=---/L=---/O=kickitout.net/OU=sieben/CN=sieben.kickitout.net/emailAddress=webmaster@kickitout.net"
# CRT
openssl x509 -req -sha512 -days 3650 -in server.csr -signkey server.key -out server.crt
# KEY check
openssl ecparam -check -noout -in server.key
# CSR check
openssl req -verify -noout -in server.csr
# CRT subject
openssl x509 -noout -subject -in server.crt
chrome42だとsecp521r1が駄目みたい
scp384r1なら行ける
openssl ecparam -genkey -name secp384r1 -genkey -out server.key
コメントを投稿