OpenSSL 3.1.0 on Alpine Linux 3.17.3 with libfaketime 0.9.10 (18 MB)
1.6K
The main goal of this container is to have the latest OpenSSL version with libfaketime to be able to generate certificate either in the past or in the future for testing.

Docker Container with Alpine Linux 3.17.3, OpenSSL 3.1.0 and libfaketime 0.9.10.
docker pull ddella/openssl
Run the container with an interactive shell. As soon as you exit the shell, the container is terminated:
docker run -it --rm --entrypoint /bin/sh --name openssl --hostname=openssl openssl
Use OpenSSL as you would normally do:
openssl:~# openssl version
Output:
OpenSSL 3.1.0 14 Mar 2023 (Library: OpenSSL 3.1.0 14 Mar 2023)
If you want to test the libfaketime library, use this command:
openssl:~# LD_PRELOAD=libfaketime.so.1 FAKETIME="2025-01-01 10:10:00" FAKETIME_DONT_RESET=1 /bin/date
Run the container in detach mode, with local volume and OpenSSH. This maps your local ~/Downloads directory to the container’s /var/tmp directory. Everything the container read/write on /var/tmp will be read/write on your local ~/Downloads directory. Adapt to your needs.
docker run --rm -d -p 2222:22 --name openssl -v ~/Downloads/:/var/tmp --hostname=openssl openssl
Adapt the volume mapping to your needs.
SSH to the container with username root: (password is root) 😀
ssh -l root -p 2222 127.0.0.1
SSH to the container with username remote with: (password is on the banner page)
ssh -l remote -p 2222 127.0.0.1
Use the following command to create an X509 certificate either in the past or future. The following commands are executed inside the container:
openssl:~# cd /var/tmp/
openssl:~# LD_PRELOAD=libfaketime.so.1 FAKETIME="2035-01-01 10:10:00" ./self_signed_ecc.sh bogus_certificate
You can use OpenSSL without libfaketime. Just use OpenSSL as you would normally. The following commands are executed inside the container:
openssl:~# cd /var/tmp/
openssl:~# ./self_signed_ecc.sh bogus_certificate
or any OpenSSL commands:
openssl:~# cd /var/tmp/
openssl:~# openssl --help
The script
self_signed_ecc.shgenerates a self-signed certificate with ECC keys and can be found on my Gist here. I also made a script to generate self-signed certificate with RSA keys here. Adapt to your needs.
Use this command to terminate the container:
docker rm -f openssl
Content type
Image
Digest
sha256:cb6ae5c1d…
Size
16.1 MB
Last updated
over 3 years ago
docker pull ddella/openssl