vediamo come creare una nostra certification authority e firmare un certificato.
$ mkdir demoCA && mkdir demoCA/private && mkdir demoCA/newcerts $ echo "01" > demoCA/serial $ touch demoCA/index.txt $ openssl req -new -x509 -keyout demoCA/private/cakey.pem -out demoCA/cacert.pem -days 3650
$ openssl req -new -nodes -keyout newreq.pem -out newreq.pem -days 3650
$ openssl ca -policy policy_anything -out newcert.pem -infiles newreq.pem