A simple Docker image to create certificate requests for web servers
1.2K
A simple Docker image to create certificate requests for web servers
docker build -t gunet/cert-req:latest .docker run --rm -e ORG=<ORG> -e SERVER=<hostname> -v $PWD/certs:/var/cert-req/certs gunet/cert-req <argument>docker run --rm -e ORG=sch.gr -e SERVER=sso-01-test.sch.gr -v $PWD/certs:/var/cert-req/certs gunet/cert-req create-it option.$PWD/certscreate: Create a new private key and server.csrprint: Print CSRrenew: Regenerate the CSR reusing the same keyencrypt: Encrypt the private key with a pass phrasedecrypt: Remove the passphrase from an encrypted keyencrypt-file: Encrypt the file provided in the FILE environment variable with the PASSPHRASE (or we will request it) with symmetrical encryption. The resulting file will get a .aes extensiondecrypt-file: Decrypt the file with symmetrical encryption. For the output file we remove the .aes extension. If it does not exist, we fail.self-sign: Create a new private key and CSR and self-sign the certificate.self-sign-ca: Create a CA, a private key and CSR and self-sign a certificate. The certs/ folder will include the CSR and private key.resign-ca: Re-sign the server certificate using the existing CA.dh: Create a dh.pem DH parameters filePASSPHRASE is present then that will be usedself-sign or self-sign-ca then we will use it to encrypt the private key as well.server.crtserver.csrprivkey.pemprivkey.keydocker-compose builddocker-compose run -e ORG=<ORG> -e SERVER=<hostname> --rm cert-req <command>ORG: Organization (ie GUNET)SERVER: The server DNS namePASSPHRASE: The passphrase to use when encryting/decrypting. If it is not passed as an environment variable, it will be requested (you need to pass -it option in this case)SUBJALTNAMES: A comma separated list of subAltNames to be included in the certificate request/self-signed certificate.FILE: The (absolute) path (in the container context) for a file to be encrypted or decryptedopenssl req -new -newkey rsa:4096 -nodes -keyout privkey.pem -out server.csr -config server.cnf -batchopenssl req -x509 -newkey rsa:4096 -nodes -keyout privkey.pem -out server.csr -config server.cnd -sha256 -days 7300 -batchopenssl req -x509 -in server.csr -config server.cnf -key privkey.pem -out server.crt -days 7300 -sha256 -batchopenssl req -new -key certs/privkey.pem -out certs/server.csr -config server.cnf -batchopenssl req -text -noout -verify -in certs/server.csropenssl rsa -text -noout -in <name of key>.keyopenssl rsa -aes256 -passout PASS -in <unencrypted name> -out <encrypted name>
des are not supported by default by OpenSSL v3.0 and should not be usedopenssl rsa -in <encrypted name> -out <unencrypted name>openssl rsa -passin PASS -in <encrypted named> -out <unencrypted name>.pem and the encrypted in .keyopenssl enc -aes-256-cbc -md sha512 -pbkdf2 -iter 100000 -salt -pass PASS -in <unencrypted> -out <encrypted>openssl enc -aes-256-cbc -md sha512 -pbkdf2 -iter 100000 -salt -d -pass PASS -in <encrypted> -out <unencrypted>PASS can be one of:
pass:${PASS}: A text passphraseenv:PASS: The passphrase will take the value of the environment variable PASSopenssl dhparam -out certs/dh.pem 4096openssl x509 -text -in server.crtAuthority Information Access endpoint): openssl x509 -text -inform der -in <cert-file>openssl crl2pkcs7 -nocrl -certfile server.crt | openssl pkcs7 -print_certs -nooutopenssl x509 -noout -modulus -in server.crt| openssl md5openssl rsa -noout -modulus -in privkey.pem| openssl md5openssl req -noout -modulus -in server.csr| openssl md5openssl x509 -noout -enddate -in server.crtopenssl x509 -noout -dates -in server.crtopenssl x509 -noout -checkend <seconds> -in server.crthttps://crt.sh/?Identity=<domaain>&exclude=expired&deduplicate=Y&output=jsonopenssl s_client to directly connect to a server and check the TLS protocolopenssl s_client -connect <name>:443time echo "Q" | openssl s_client -connect <name>:443 2>1 >/dev/null-servername argument then openssl also does SNI-quiet and the -crlf options# openssl s_client -connect sso.asfa.gr:443 -quiet -crlf
GET /login HTTP/1.1
Host: sso.asfa.gr
openssl s_client -quiet -connect relay.grnet.gr:587 -starttls smtp-quiet flag is important in order to be able to issue capitalized SMTP commands with no problem.# openssl s_client -quiet -connect relay.grnet.gr:587 -starttls smtp
depth=2 C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority
verify return:1
depth=1 C = NL, O = GEANT Vereniging, CN = GEANT OV RSA CA 4
verify return:1
depth=0 C = GR, ST = Attik\C3\AD, O = National Infrastructures for Research and Technology, CN = relay.grnet.gr
verify return:1
250 HELP
MAIL FROM: <[email protected]>
250 OK
RCPT TO: <[email protected]>
250 Accepted
DATA
354 Enter message, ending with "." on a line by itself
Subject: Test
test
.
250 OK id=1q6SbR-0007fb-Tr
QUIT
221 relay.grnet.gr closing connection
# echo -n "username" | base64
dXNlcm5hbWU=
# echo -n "password" | base64
cGFzc3dvcmQ=
(cut)
250 8BITMIME
AUTH LOGIN
334 VXNlcm5hbWU6
dXNlcm5hbWU=
334 UGFzc3dvcmQ6
cGFzc3dvcmQ=
235 2.7.0 Authentication successful
testssl.sh can run a set of SSL/TLS tests against a server. A Docker image is availabledocker run --rm -ti drwetter/testssl.sh <host>[:<port>]openssl s_time -connect <host>:<port>openssl speed test with:
openssl speed -evp aes-256-gcm to test the AES-256-GCM cipher familyopenssl speed -evp aes-256-cbc to test the AES-256-CBC cipher familyOPENSSL_ia32cap=0 environment variable to disable the AES-NI instruction setContent type
Image
Digest
sha256:3f50e7e74…
Size
30.3 MB
Last updated
about 2 years ago
docker pull gunet/cert-req