Generate a Certificate Signing Request (CSR) File for Cisco ASA
To generate a
certificate signing request (CSR) for Cisco ASA 5510, perform the following
steps:
Step 1: Generate a key pair
1.
Within ASDM, click Configuration > Device
Management
2.
Click Certificate Management > Identity
Certificates > Add > Add a new identity
certificate
3.
For the Key Pair, click New > Enter
new key pair name
4.
Enter a unique key pair name for the certificate
5.
Select the key size as 2048
6.
To complete the generation of the key pair, click Generate
Now
Step 2: Generate a certificate signing request (CSR)
file
1.
To enter certificate information, click Select
2.
From the drop-down list, select the following attributes >
enter value > click Add
Note: The following fields are required: C (Country), St (State), L (Locality), O (Organization Name), OU (Organizational Unit), CN (Common Name)
Note: The following fields are required: C (Country), St (State), L (Locality), O (Organization Name), OU (Organizational Unit), CN (Common Name)
3.
Once the appropriate values are added, click OK > Advanced
4.
In the FQDN field, enter the FQDN that will be used to access
the device from the Internet: NOTE - If enrolling for a Subject
Alternative Name certificate leave this field blank.
Note: This value should be same FQDN you used for the Common Name (CN)
Note: This value should be same FQDN you used for the Common Name (CN)
5.
Click OK > Add Certificate > Browse
6.
Choose a location where to save the request file
Most Imp .Java Keytool Commands
Generate a Java keystore and key pair:keytool -genkey
-alias mydomain -keyalg RSA -keystore keystore.jks -keysize
2048
Generate
a certificate signing request (CSR) for an existing Java keystore:
keytool -certreq
-alias mydomain -keystore keystore.jks -file mydomain.csr
Generate
a keystore and self-signed certificate:
keytool -genkey -keyalg
RSA -alias selfsigned -keystore keystore.jks
-storepass password -validity 360 -keysize 2048
Certificate import commands in keystore:
Import a root CA certificate to an existing
Java keystore:
keytool -import -trustcacerts
-alias root -file root.crt -keystore keystore.jks
Import a
intermediate CA certificate to an existing Java keystore:
keytool -import -trustcacerts
-alias intermediate -file
intermediate.crt -keystore keystore.jks
Import a signed SSL primary certificate to an
existing Java keystore:
keytool -import -trustcacerts
-alias mydomain -file mydomain.crt -keystore keystore.jks
Java Keytool Commands for Conversion:
If you need to change the type of
keystore.
PFX keystore to JKS keystore:
keytool -importkeystore -srckeystore mypfxfile.pfx -srcstoretype
pkcs12 -destkeystore newjkskeystore.jks -deststoretype JKS
JKS keystore to PFX keystore:
keytool -importkeystore
-srckeystore myjksfile.jks -srcstoretype JKS -deststoretype PKCS12
-destkeystore newpfxkeystore.pfx
Other Java Keytool Commands:
Delete a certificate from a Java Keytool keystore:
keytool -delete -alias mydomain -keystore keystore.jks
Change a Java keystore password:
keytool -storepasswd -new newstorepass -keystore keystore.jks
Export a certificate from a keystore:
keytool -export -alias mydomain -file mydomain.crt
-keystore keystore.jks
List Trusted CA Certs:
keytool -list -v -keystore
$JAVA_HOME/jre/lib/security/cacerts
Import New CA into Trusted Certs:
keytool -import -trustcacerts
-file /path/to/ca/ca.pem -alias mydomain -keystore
$JAVA_HOME/jre/lib/security/cacertsMost OpenSSL Commands
Convert
PEM to DER:
openssl
x509 -outform der -in certificate.pem -out certificate.der
Convert DER to PEM:
openssl
x509 -inform der -in certificate.der -out certificate.pem
Convert PEM/CRT to P7B:
openssl
crl2pkcs7 -nocrl -certfile certificate.crt -out certificate.p7b
-certfile CACert.crt
Convert P7B to PEM/CRT:
openssl
pkcs7 -print_certs -in certificate.p7b
-out certificate.crt
Convert
PEM/CRT & Private Key to PFX/P12:
openssl
pkcs12 -export -out certificate.pfx
-inkey privateKey.key -in certificate.crt -certfile CACert.crt
Convert
P7B to PFX:
openssl
pkcs12 -export -in certificate.cer -inkey privateKey.key -out certificate.pfx
-certfile CACert.cer
Convert PFX to PEM/CRT and Private Key
openssl pkcs12 -in certificate.pfx
-out certificate.crt -nodes
OpenSSL command to remove private key
password
Or
To convert simple private to RSA
private.key
openssl
rsa -in file.key -out newfile.key openssl
command print out
md5 checksums of the certificate and key openssl
x509 -noout -modulus -in server.crt| openssl md5 openssl rsa -noout -modulus -in server.key|
openssl md5 Installing SSL Certificate on Zimbra
Using the CLI
·
1. Get the certificate from ssl authority in crt/txt format, or
sometimes like a zip file.
·
2. Place the Certificate on your Zimbra mailbox server. You
should receive below files:
o Root.crt
o Intermediate.crt
o My_Domain_com.crt
files
Note the root and
intermediate files may have different names depends of the SSL Certificate,
like DigiCert etc.
Note 2 all the below
commands should be run as zimbra user starting ZCS 8.7 and above, and
as a root user in ZCS 8.6 and below.
·
3. Cat the CA certs to form a single CA certificate chain file
cat Root.crt Intermediate.crt > /tmp/commercial_ca.crt
·
4. Place the SSL certificate in /tmp/commercial.crt.
cp my_domain_com.crt /tmp/commercial.crt
·
5. Copy private key file (which is generate at a time of CSR generation)
on below path and rename it commercial.key .
/opt/Zimbra/ssl/Zimbra/commercial/commercial.key
·
6. Check that your SSL certificate, your private key and the
Intermediate CA are OK, this step is important and you should not continue if
you receive an error here:
/opt/zimbra/bin/zmcertmgr
verifycrt comm /opt/zimbra/ssl/zimbra/commercial/commercial.key
/tmp/commercial.crt /tmp/commercial_ca.crt
** Verifying /tmp/commercial.crt
against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/tmp/commercial.crt)
and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate:
/tmp/commercial.crt: OK
·
7. Deploy the commercial certificate with zmcertmgr as the Zimbra
user.
/opt/zimbra/bin/zmcertmgr
deploycrt comm /tmp/commercial.crt /tmp/commercial_ca.crt
** Verifying /tmp/commercial.crt
against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/tmp/commercial.crt)
and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate:
/tmp/commercial.crt: OK
** Copying /tmp/commercial.crt to
/opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Appending ca chain /tmp/commercial_ca.crt
to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Importing certificate
/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt to CACERTS as
zcs-user-commercial_ca...done.
** NOTE: mailboxd must be
restarted in order to use the imported certificate.
** Saving server config key
zimbraSSLCertificate...done.
** Saving server config key
zimbraSSLPrivateKey...done.
** Installing mta certificate and
key...done.
** Installing slapd certificate
and key...done.
** Installing proxy certificate and
key...done.
** Creating pkcs12 file
/opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
** Creating keystore file
/opt/zimbra/mailboxd/etc/keystore...done.
** Installing CA to
/opt/zimbra/conf/ca...done.
·
8. Restart the Zimbra Services
zmcontrol restart
Subscribe to:
Posts (Atom)