[root@test1
2.0
]# ./build-key test2.test.com
Generating a
1024
bit RSA
private
key
............................................................................................................................++++++
......................++++++
writing
new
private
key to
'test2.test.com.key'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter
is
what
is
called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a
default
value,
If you enter
'.'
, the field will be left blank.
-----
Country Name (
2
letter code) [CN]:
State or Province Name (full name) [HB]:
Locality Name (eg, city) [WH]:
Organization Name (eg, company) [test.com]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) [test2.test.com]: 每个client的hostname都不能一样
Name []:
Email Address [root@localhost]:
Please enter the following
'extra'
attributes
to be sent
with
your certificate request
A challenge password []:
123456
An optional company name []:
Using configuration from /etc/openvpn/easy-rsa/
2.0
/openssl.cnf
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name
is
as
follows
countryName :PRINTABLE:
'CN'
stateOrProvinceName :PRINTABLE:
'HB'
localityName :PRINTABLE:
'WH'
organizationName :PRINTABLE:
'test.com'
commonName :PRINTABLE:
'test2.test.com'
emailAddress :IA5STRING:
'root@localhost'
Certificate
is
to be certified until Oct
6
03
:
36
:
48
2023
GMT (
3650
days)
Sign the certificate? [y/n]:y
1
out of
1
certificate requests certified, commit? [y/n]y
Write out database
with
1
new
entries
Data Base Updated