Sign inSign up

ddella/openssl

By ddella

•Updated over 3 years ago

OpenSSL 3.1.0 on Alpine Linux 3.17.3 with libfaketime 0.9.10 (18 MB)

Image
0

1.6K

ddella/openssl repository overview

⁠OpenSSL on Alpine Linux

The main goal of this container is to have the latest OpenSSL version with libfaketime to be able to generate certificate either in the past or in the future for testing.

description

Docker Container with Alpine Linux 3.17.3, OpenSSL 3.1.0 and libfaketime 0.9.10.

⁠Installation

docker pull ddella/openssl

⁠How to use this image

⁠Interactive Shell

Run the container with an interactive shell. As soon as you exit the shell, the container is terminated:

docker run -it --rm --entrypoint /bin/sh --name openssl --hostname=openssl openssl

Use OpenSSL as you would normally do:

openssl:~# openssl version

Output:

OpenSSL 3.1.0 14 Mar 2023 (Library: OpenSSL 3.1.0 14 Mar 2023)

If you want to test the libfaketime library, use this command:

openssl:~# LD_PRELOAD=libfaketime.so.1 FAKETIME="2025-01-01 10:10:00" FAKETIME_DONT_RESET=1 /bin/date
⁠Detached mode

Run the container in detach mode, with local volume and OpenSSH. This maps your local ~/Downloads directory to the container’s /var/tmp directory. Everything the container read/write on /var/tmp will be read/write on your local ~/Downloads directory. Adapt to your needs.

docker run --rm -d -p 2222:22 --name openssl -v ~/Downloads/:/var/tmp --hostname=openssl openssl

Adapt the volume mapping to your needs.

SSH to the container with username root: (password is root) 😀

ssh -l root -p 2222 127.0.0.1

SSH to the container with username remote with: (password is on the banner page)

ssh -l remote -p 2222 127.0.0.1
⁠With libfaketime

Use the following command to create an X509 certificate either in the past or future. The following commands are executed inside the container:

openssl:~# cd /var/tmp/
openssl:~# LD_PRELOAD=libfaketime.so.1 FAKETIME="2035-01-01 10:10:00" ./self_signed_ecc.sh bogus_certificate
⁠Without libfaketime

You can use OpenSSL without libfaketime. Just use OpenSSL as you would normally. The following commands are executed inside the container:

openssl:~# cd /var/tmp/
openssl:~# ./self_signed_ecc.sh bogus_certificate

or any OpenSSL commands:

openssl:~# cd /var/tmp/
openssl:~# openssl --help

The script self_signed_ecc.sh generates a self-signed certificate with ECC keys and can be found on my Gist here⁠. I also made a script to generate self-signed certificate with RSA keys here⁠. Adapt to your needs.

⁠Terminate the container

Use this command to terminate the container:

docker rm -f openssl

Tag summary

Content type

Image

Digest

sha256:cb6ae5c1d…

Size

16.1 MB

Last updated

over 3 years ago

docker pull ddella/openssl