<xmp>
::生成根证书key
openssl genpkey -algorithm RSA -out rootCA.key -pkeyopt rsa_keygen_bits:2048
::生成根证书
openssl req -x509 -new -nodes -key rootCA.key -sha256 -days 3650 -out rootCA.pem -config rootCA.conf -extensions ext & copy /y rootCA.pem rootCA.crt
::生成服务器key
openssl genpkey -algorithm RSA -out server.key -pkeyopt rsa_keygen_bits:2048
::生成服务器csr
openssl req -new -key server.key -out server.csr -config server.csr.conf
::颁发证书
openssl x509 -req -in server.csr -CA rootCA.pem -CAkey rootCA.key -CAcreateserial -out server.crt -days 825 -sha256 -extfile domain_info.conf
:err
pause</xmp>
1