Generate a Certificate Signing Request (CSR) File for Cisco ASA


To generate a certificate signing request (CSR) for Cisco ASA 5510, perform the following steps:
Step 1:  Generate a key pair
1.    Within ASDM, click Configuration > Device Management
2.    Click Certificate Management > Identity Certificates > Add > Add a new identity certificate
3.    For the Key Pair, click New > Enter new key pair name
4.    Enter a unique key pair name for the certificate
5.    Select the key size as 2048
6.    To complete the generation of the key pair, click Generate Now

Step 2: Generate a certificate signing request (CSR) file
1.    To enter certificate information, click Select
2.    From the drop-down list, select the following attributes > enter value > click Add
Note: The following fields are required: C (Country), St (State), L (Locality), O (Organization Name), OU (Organizational Unit), CN (Common Name)
3.    Once the appropriate values are added, click OK > Advanced
4.    In the FQDN field, enter the FQDN that will be used to access the device from the Internet: NOTE - If enrolling for a Subject Alternative Name certificate leave this field blank.
Note: This value should be same FQDN you used for the Common Name (CN)
5.    Click OK >  Add Certificate > Browse
6.    Choose a location where to save the request file


Most Imp .Java Keytool Commands



      Generate a Java keystore and key pair:

            keytool -genkey -alias mydomain -keyalg RSA -keystore keystore.jks -keysize 2048
    Generate a certificate signing request (CSR) for an existing Java keystore: 
            keytool -certreq -alias mydomain -keystore keystore.jks -file mydomain.csr
    Generate a keystore and self-signed certificate:
           keytool -genkey -keyalg RSA -alias selfsigned -keystore keystore.jks -storepass password -validity 360 -keysize 2048
     
Certificate import commands in keystore:
Import a root CA certificate to an existing Java keystore:
               keytool -import -trustcacerts -alias root -file root.crt -keystore keystore.jks
           Import a intermediate CA certificate to an existing Java keystore:
              keytool -import -trustcacerts -alias intermediate -file intermediate.crt -keystore keystore.jks
Import a signed SSL primary certificate to an existing Java keystore:
                keytool -import -trustcacerts -alias mydomain -file mydomain.crt -keystore keystore.jks

    Java Keytool Commands for Conversion:

             If you need to change the type of keystore.
PFX keystore to JKS keystore:
keytool -importkeystore -srckeystore mypfxfile.pfx -srcstoretype pkcs12 -destkeystore newjkskeystore.jks -deststoretype JKS
JKS keystore to PFX keystore:
keytool -importkeystore -srckeystore myjksfile.jks -srcstoretype JKS -deststoretype PKCS12 -destkeystore newpfxkeystore.pfx
    Other Java Keytool Commands:
Delete a certificate from a Java Keytool keystore:
keytool -delete -alias mydomain -keystore keystore.jks
Change a Java keystore password:
keytool -storepasswd -new newstorepass -keystore keystore.jks
Export a certificate from a keystore:
keytool -export -alias mydomain -file mydomain.crt -keystore keystore.jks
List Trusted CA Certs:
keytool -list -v -keystore $JAVA_HOME/jre/lib/security/cacerts
Import New CA into Trusted Certs:
keytool -import -trustcacerts -file /path/to/ca/ca.pem -alias mydomain -keystore $JAVA_HOME/jre/lib/security/cacerts

Most OpenSSL Commands




      Convert PEM to DER:
       openssl x509 -outform der -in certificate.pem -out certificate.der

       Convert DER to PEM:
       openssl x509 -inform der -in certificate.der -out certificate.pem

       Convert PEM/CRT to P7B:
       openssl crl2pkcs7 -nocrl -certfile certificate.crt -out certificate.p7b -certfile CACert.crt

       Convert P7B to PEM/CRT:
       openssl pkcs7 -print_certs -in certificate.p7b -out certificate.crt


        Convert PEM/CRT & Private Key to PFX/P12:
       openssl pkcs12 -export -out certificate.pfx -inkey privateKey.key -in certificate.crt -certfile CACert.crt

        Convert P7B to PFX:
        openssl pkcs12 -export -in certificate.cer -inkey privateKey.key -out certificate.pfx -certfile CACert.cer

        Convert PFX to PEM/CRT and Private Key
                 openssl pkcs12 -in certificate.pfx -out certificate.crt -nodes

   


         OpenSSL command to remove private key password
                                              Or
          To convert simple private to   RSA   private.key

        openssl rsa -in file.key -out newfile.key
   
    openssl command print out md5 checksums of the certificate and key
        openssl x509 -noout -modulus -in server.crt| openssl md5
                openssl rsa -noout -modulus -in server.key| openssl md5
   




Installing SSL Certificate on Zimbra


Using the CLI
·         1. Get the certificate from ssl authority in crt/txt format, or sometimes like a zip file.
·         2. Place the Certificate on your Zimbra mailbox server. You should receive below files:
o    Root.crt
o    Intermediate.crt
o    My_Domain_com.crt files
Note the root and intermediate files may have different names depends of the SSL Certificate, like DigiCert etc.
Note 2 all the below commands should be run as zimbra user starting ZCS 8.7 and above, and as a root user in ZCS 8.6 and below.
·         3. Cat the CA certs to form a single CA certificate chain file
 cat Root.crt Intermediate.crt > /tmp/commercial_ca.crt
·         4. Place the SSL certificate in /tmp/commercial.crt.
 cp my_domain_com.crt /tmp/commercial.crt
·         5. Copy private key file (which is generate at a time of CSR generation) on below path and rename it  commercial.key  .
/opt/Zimbra/ssl/Zimbra/commercial/commercial.key
·         6. Check that your SSL certificate, your private key and the Intermediate CA are OK, this step is important and you should not continue if you receive an error here:
/opt/zimbra/bin/zmcertmgr verifycrt comm /opt/zimbra/ssl/zimbra/commercial/commercial.key /tmp/commercial.crt /tmp/commercial_ca.crt
** Verifying /tmp/commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/tmp/commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate: /tmp/commercial.crt: OK
·         7. Deploy the commercial certificate with zmcertmgr as the Zimbra user.
/opt/zimbra/bin/zmcertmgr deploycrt comm /tmp/commercial.crt /tmp/commercial_ca.crt
** Verifying /tmp/commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/tmp/commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate: /tmp/commercial.crt: OK
** Copying /tmp/commercial.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Appending ca chain /tmp/commercial_ca.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Importing certificate /opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt to CACERTS as zcs-user-commercial_ca...done.
** NOTE: mailboxd must be restarted in order to use the imported certificate.
** Saving server config key zimbraSSLCertificate...done.
** Saving server config key zimbraSSLPrivateKey...done.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
** Installing CA to /opt/zimbra/conf/ca...done.
·         8. Restart the Zimbra Services
zmcontrol restart


            SSL Configuring step for IBM Http Server 


Creating new SSL digital Certificate using iKeyman:

For the certificate you can use either a certificate that is signed by a certificate authority or you can also use a self-signed certificate.  Before creating a new certificate, you need to create a certificate store or Key Database.
  • start the iKeyman utility: /IHS root/bin/ikeyman.sh
  • From the Menu Bar select Key Database File > New.
  • Choose the key database type as CMS
  • Enter a file name for the new Key Database file you are creating
  • Enter a Location for the location where you want to store the .kdb file



  • Click OK
  • After saving the key database file to the location specified, you are prompted to enter a password. This is the password that will be used to open the key database file in iKeyman in the future.
  • make sure checkbox Stash the password to a file is enabled. this saves the encrypted password file as a .sth file in the same directory as the key database file.



  • Now Click OK
Your Key Database file is Ready.
Now let's create a certificate request. I am using this URL for my site sslsupport.blogspot.com
  • First, Open the KDB using ikeyman. This will show the key database contents.
  • Click on the “down arrow” to the right, to display a list of three choices.




Select Personal Certificate Requests and click New

Now, a new window will pop up. here

you need to input details about the certificate and your organization.


Options:
  • Key Size= 2048 for 256bit and 512bit
  • Common Name= SiteName, [This is the name that the CA will register]
  • Organization= Company Name
  • Enter the name of a file in which to store the certificate request = This is the file (.arm) that will contain your request
Once you save the file (.arm) you are done with creating the request
You must now choose a CA and send them a “Certificate Request”
Once the CA has signed your certificate, generally they send you back the signed certificate through email.
  • Take the information provided in the CAs email and copy it to a text file (notepad) and save it as IHS_Root/SSL/CertRcvd.arm
  • Open the KDB file and choose Personal Certificates from the drop-down options [ check image3 for how-to]
  • From the Personal Certificates section, click Receive, a pop-up window will come


Input the required data. Like  certificate name and location and click OK




Preparing IHS for SSL:
Open the httpd.conf file for editing and modify it to implement the following:
  • For the host_name.domain, use the virtual host IP address or fully qualified domain name.
  • Typically, port 443 is used for HTTPS protocol.
  • The timeout values are given in seconds. Your values might be different.
Sample httpd.conf file for a UNIX computer:
    LoadModule ibm_ssl_module libexec/mod_ibm_ssl.so
AddModule mod_ibm_ssl.c
Listen 443
<VirtualHost host_name.domain:443>
ServerName host_name.domain
SSLServerCert certificate name
DocumentRoot “IHS_Root\docs”
SSLEnable
SSLClientAuth none
<\VirtualHost>
SSLDisable
Keyfile “path_to_keyfile_created”
SSLV2Timeout 100
SSLV3Timeout 1000
Restart IBM HTTP Server for the changes take effect.
Example SSL virtualhost :
<VirtualHost xxx.xxx.xx.xx:443>
ServerName test.com

SSLEnable
SSLClientAuth None
SSLServerCert mywebsite
<Directory “/home/www/website”>
Options Indexes
AllowOverride None
order allow,deny
allow from all
</Directory>
DocumentRoot “/home/www/website”
</VirtualHost>