maroph icon

Java 8 keytool: Create key pair and a self-signed cert

maroph | PRO | 05/04/18 10:51:53 AM UTC | 0 ⭐ | 301 👁️ | Never ⏰ | []
text |

3.38 KB

|

None

|

0 👍

/

0 👎

# Create a PKCS12 keystore which contains one key pair with a self-signed certificate
#
keytool \
    -genkeypair \
    -keystore ./wec.p12 \
    -storepass topsecret \
    -storetype PKCS12 \
    -alias wec \
    -dname "CN=Wile E. Coyote, OU=Rocket-Powered Products Department, O=ACME Corporation, L=Fairfield, ST=New Jersey, C=US" \
    -keyalg RSA \
    -keysize 4096 \
    -sigalg SHA256WithRSA \
    -validity 365 \
    -v
#
# List the keystore content
#
keytool -list -keystore ./wec.p12 -storepass topsecret -storetype PKCS12 -v
Keystore type: PKCS12
Keystore provider: SunJSSE
 Your keystore contains 1 entry
 Alias name: wec
Creation date: May 4, 2018
Entry type: PrivateKeyEntry
Certificate chain length: 1
Certificate[1]:
Owner: CN=Wile E. Coyote, OU=Rocket-Powered Products Department, O=ACME Corporation, L=Fairfield, ST=New Jersey, C=US
Issuer: CN=Wile E. Coyote, OU=Rocket-Powered Products Department, O=ACME Corporation, L=Fairfield, ST=New Jersey, C=US
Serial number: 61ccf131
Valid from: Fri May 04 12:20:10 CEST 2018 until: Sat May 04 12:20:10 CEST 2019
Certificate fingerprints:
         MD5:  FB:9C:5F:46:FE:03:08:9F:C4:A8:3F:60:54:CA:B0:CF
         SHA1: C1:D2:29:65:BC:6E:6D:3E:F4:29:58:0E:6E:2B:3E:73:00:2C:8D:FD
         SHA256: 64:25:1B:C7:F8:B7:87:53:57:86:D3:53:8C:10:E3:E9:75:FA:FE:FC:64:23:2D:5D:A3:95:CB:3F:68:29:1A:FC
Signature algorithm name: SHA256withRSA
Subject Public Key Algorithm: 4096-bit RSA key
Version: 3
 Extensions:
 #1: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 03 72 9C BB 1C C4 7B BD   27 C3 D5 1F D9 CE 62 6D  .r......'.....bm
0010: 6C 9A 79 E5                                        l.y.
]
]
   *******************************************
*******************************************
 #
# Export the certificate 
#
keytool \
    -exportcert \
    -keystore ./wec.p12 \
    -storepass topsecret \
    -storetype PKCS12 \
    -alias wec \
    -file wec.cer \
    -v
#
keytool \
    -exportcert \
    -rfc \
    -keystore ./wec.p12 \
    -storepass topsecret \
    -storetype PKCS12 \
    -alias wec \
    -file wec.rfc.cer \
    -v
#
cat wec.rfc.cer
-----BEGIN CERTIFICATE-----
MIIFzzCCA7egAwIBAgIEYczxMTANBgkqhkiG9w0BAQsFADCBlzELMAkGA1UEBhMC
...
w70xryAftJrOy9lQ+oEDOjDd03nIpLbPWm+6Hs0zguxNUTOGZ4m4r/vwRa/HdQAC
/yR/
-----END CERTIFICATE-----
#
# Show the certificate data
#
keytool -printcert -file wec.cer -v
Owner: CN=Wile E. Coyote, OU=Rocket-Powered Products Department, O=ACME Corporation, L=Fairfield, ST=New Jersey, C=US
Issuer: CN=Wile E. Coyote, OU=Rocket-Powered Products Department, O=ACME Corporation, L=Fairfield, ST=New Jersey, C=US
Serial number: 61ccf131
Valid from: Fri May 04 12:20:10 CEST 2018 until: Sat May 04 12:20:10 CEST 2019
Certificate fingerprints:
         MD5:  FB:9C:5F:46:FE:03:08:9F:C4:A8:3F:60:54:CA:B0:CF
         SHA1: C1:D2:29:65:BC:6E:6D:3E:F4:29:58:0E:6E:2B:3E:73:00:2C:8D:FD
         SHA256: 64:25:1B:C7:F8:B7:87:53:57:86:D3:53:8C:10:E3:E9:75:FA:FE:FC:64:23:2D:5D:A3:95:CB:3F:68:29:1A:FC
Signature algorithm name: SHA256withRSA
Subject Public Key Algorithm: 4096-bit RSA key
Version: 3
 Extensions:
 #1: ObjectId: 2.5.29.14 Criticality=false
SubjectKeyIdentifier [
KeyIdentifier [
0000: 03 72 9C BB 1C C4 7B BD   27 C3 D5 1F D9 CE 62 6D  .r......'.....bm
0010: 6C 9A 79 E5                                        l.y.
]
]

Comments