|
|
安装的软件:
openswan(Linux Openswan U2.4.6/K2.4.9 (klips))
openssl(OpenSSL 0.9.8c 05 Sep 2006)
近日尝试向windows客户端颁发证书,各命令行如下:
/usr/lib/ssl/misc/CA.sh -newca
openssl ca -gencrl -out crl.pem
/usr/lib/ssl/misc/CA.sh -newreq
/usr/lib/ssl/misc/CA.sh -sign
mv newcert.pem winhost.pem
mv newreq.pem winhost.key
cp /var/sslca/winhost.key /etc/ipsec.d/private
cp /var/sslca/winhost.pem /etc/ipsec.d/certs
cp /var/sslca/demoCA/cacert.pem /etc/ipsec.d/cacerts
cp /var/sslca/crl.pem /etc/ipsec.d/crls/crl.pem
openssl pkcs12 -export -in winhost.pem -inkey winhost.key -certfile demoCA/cacert.pem -out winhost.p12
但是在最后导出p12的时候总是提示:unable to load private key.
请各位不吝赐教! |
|