LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-17-2008, 06:54 AM   #1
kenneho
Member
 
Registered: May 2003
Location: Oslo, Norway
Distribution: Ubuntu, Red Hat Enterprise Linux
Posts: 657

Rep: Reputation: 40
Creating SSL sertificate request in RHEL 5


Hello all.


A few day ago I made a SSL certificate request on my RHEL 5 server, using the /etc/pki/tls/certs/Makefile script that ships with the distribution. The command I used for making the request was "make certreq".

Due to a typo I tried to rerun the script, but know I'm asked to create a passphrase. Anyone knows why I'm asked to create a passphrase now, and why I wasn't asked to do so the first time? What is this passphrase protecting anyways?


Regards,
kenneho
 
Old 09-18-2008, 02:28 AM   #2
datopdog
Member
 
Registered: Feb 2008
Location: JHB South Africa
Distribution: Centos, Kubuntu, Cross LFS, OpenSolaris
Posts: 806

Rep: Reputation: 41
The passphrase is used to protect your private key.
 
Old 09-18-2008, 06:03 AM   #3
kenneho
Member
 
Registered: May 2003
Location: Oslo, Norway
Distribution: Ubuntu, Red Hat Enterprise Linux
Posts: 657

Original Poster
Rep: Reputation: 40
Quote:
Originally Posted by datopdog View Post
The passphrase is used to protect your private key.
When I ran through the script the first time to generate the keys I was was prompted to create a password for the private key.

But why would I be prompted now when I try to generate a new pair of keys, when the keys are not ever created. Seems like it's asking me to create a password for the old key.
 
Old 09-18-2008, 06:10 AM   #4
linuxgurusa
Member
 
Registered: Mar 2008
Location: Namibia, Swakopmund
Distribution: Redhat, Fedora, Centos, ClearOS, Mandrake
Posts: 151

Rep: Reputation: 29
Quote:
Originally Posted by kenneho View Post
When I ran through the script the first time to generate the keys I was was prompted to create a password for the private key.

But why would I be prompted now when I try to generate a new pair of keys, when the keys are not ever created. Seems like it's asking me to create a password for the old key.
Just press enter without typing a password ? That is if you don't want to create one
 
Old 09-18-2008, 06:24 AM   #5
kenneho
Member
 
Registered: May 2003
Location: Oslo, Norway
Distribution: Ubuntu, Red Hat Enterprise Linux
Posts: 657

Original Poster
Rep: Reputation: 40
Quote:
Originally Posted by linuxgurusa View Post
Just press enter without typing a password ? That is if you don't want to create one
Tried that - it didn't work. :/

Just don't understand why I _must_ create a password, and which key it's supposed to guard.
 
Old 09-18-2008, 06:27 AM   #6
linuxgurusa
Member
 
Registered: Mar 2008
Location: Namibia, Swakopmund
Distribution: Redhat, Fedora, Centos, ClearOS, Mandrake
Posts: 151

Rep: Reputation: 29
Wink

Quote:
Originally Posted by kenneho View Post
Tried that - it didn't work. :/

Just don't understand why I _must_ create a password, and which key it's supposed to guard.
Are you creating a key for a SSl website you are going to use ?

I use openssl to do keys and stuff for me

openssl genrsa -out keyname.key 1024
 
Old 09-18-2008, 06:58 AM   #7
kenneho
Member
 
Registered: May 2003
Location: Oslo, Norway
Distribution: Ubuntu, Red Hat Enterprise Linux
Posts: 657

Original Poster
Rep: Reputation: 40
Quote:
Originally Posted by linuxgurusa View Post
Are you creating a key for a SSl website you are going to use ?

I use openssl to do keys and stuff for me

openssl genrsa -out keyname.key 1024
Yes I am. But the scripts shipped with RHEL user openssl to generate the keys, and I'm sure I can get the script to work without having to resort to manual prosedures. But if everything else fails I'll try your approach.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
create a new certificate request SSL Debian Linux xxsubz78x Debian 8 12-09-2007 05:22 PM
creating an SSL page under non SSL site with apache1.33? taiwf Linux - Software 1 06-27-2006 01:06 AM
SSL + Apache2 = Invalid Method in Request TruckStuff Linux - Networking 5 08-29-2004 03:29 AM
zillionth request for tut for creating and installing linux hughgjohnson Linux - Newbie 1 10-21-2003 02:05 AM
[Apache-SSL]: Invalid method in request !g!! Gahan Linux - Software 0 07-22-2003 04:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:02 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration