{"id":3072,"date":"2012-02-17T13:15:55","date_gmt":"2012-02-17T12:15:55","guid":{"rendered":"http:\/\/blogs.wittwer.fr\/whiler\/?p=3072"},"modified":"2012-03-03T04:55:38","modified_gmt":"2012-03-03T03:55:38","slug":"ssl-pour-avoir-des-trames-moins-lisibles","status":"publish","type":"post","link":"https:\/\/blogs.wittwer.fr\/whiler\/2012\/02\/17\/ssl-pour-avoir-des-trames-moins-lisibles\/","title":{"rendered":"SSL, pour avoir des trames moins lisibles"},"content":{"rendered":"<p>Sur mon <a href=\"http:\/\/fr.wikipedia.org\/wiki\/Stockage_en_r\u00e9seau_NAS\" rel=\"glossary\" target=\"_blank\" title=\"Wikipedia, D&eacute;finition de&nbsp;: NAS\" style=\"\" >NAS<\/a><sup style=\"font-family: Georgia, Times New Roman, Serif; font-weight: bold; color: #AAAAAA\" ><em>W<\/em><\/sup> <a href=\"https:\/\/www.synology.com\/index.php?lang=fre\" title=\"Site Web Synology\" target=\"_blank\">Synology<\/a>, j&rsquo;ai <a href=\"http:\/\/fr.wikipedia.org\/wiki\/OpenSSL\" rel=\"glossary\" target=\"_blank\" title=\"Wikipedia, D&eacute;finition de&nbsp;: OpenSSL\" style=\"\" >OpenSSL<\/a><sup style=\"font-family: Georgia, Times New Roman, Serif; font-weight: bold; color: #AAAAAA\" ><em>W<\/em><\/sup> qui est install\u00e9&#8230;<br \/>\nL&rsquo;acc\u00e8s n&rsquo;est pas ouvert en dehors du r\u00e9seau interne, mais j&rsquo;ai eu envie d&rsquo;effectuer quelques tests locaux&#8230; alors, je me suis pench\u00e9 sur la g\u00e9n\u00e9ration de certificats&#8230;<\/p>\n<p>Afin de pouvoir facilement le refaire ult\u00e9rieurement en cas de besoin, je mets ci-dessous les diff\u00e9rentes lignes de commande que j&rsquo;ai utilis\u00e9es&#8230; <img src=\"https:\/\/blogs.wittwer.fr\/whiler\/wp-includes\/images\/smilies\/skype\/\/wink.gif\" alt=\";)\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\" \/><\/p>\n<div class=\"codecolorer-container bash blackboard\" style=\"overflow:auto;white-space:nowrap;width:480px;height:300px;\"><div class=\"bash codecolorer\">DiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">pwd<\/span><br \/>\n<span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>syno<span class=\"sy0\">\/<\/span>mon_ssl<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw2\">ls<\/span> <span class=\"re5\">-ll<\/span><br \/>\n<span class=\"re5\">-rwxr-xr-x<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">9491<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">12<\/span>:<span class=\"nu0\">46<\/span> openssl.cnf<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> CLIENT<br \/>\nCLIENT<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> G\u00e9n\u00e9ration de la cl\u00e9 cliente<br \/>\nG\u00e9n\u00e9ration de la cl\u00e9 cliente<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> openssl genrsa <span class=\"re5\">-des3<\/span> <span class=\"re5\">-out<\/span> client.key <span class=\"nu0\">1024<\/span><br \/>\nGenerating RSA privatebashclient.key:<br \/>\nVerifying - Enter pass phrase <span class=\"kw1\">for<\/span> client.key:<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw2\">ls<\/span> <span class=\"re5\">-ll<\/span><br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">963<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:03 client.key<br \/>\n<span class=\"re5\">-rwxr-xr-x<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">9491<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">12<\/span>:<span class=\"nu0\">46<\/span> openssl.cnf<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> G\u00e9n\u00e9ration <span class=\"kw2\">du<\/span> certificat client<br \/>\nG\u00e9n\u00e9ration <span class=\"kw2\">du<\/span> certificat client<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> openssl req <span class=\"re5\">-new<\/span> <span class=\"re5\">-key<\/span> client.key <span class=\"re5\">-out<\/span> client.csr <span class=\"re5\">-config<\/span> <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>syno<span class=\"sy0\">\/<\/span>mon_ssl<span class=\"sy0\">\/<\/span>openssl.cnf<br \/>\nEnter pass phrase <span class=\"kw1\">for<\/span> client.key:<br \/>\nYou are about to be asked to enter information that will be incorporated<br \/>\ninto your certificate request.<br \/>\nWhat you are about to enter is what is called a Distinguished Name or a DN.<br \/>\nThere are quite a few fields but you can leave some blank<br \/>\nFor some fields there will be a default value,<br \/>\nIf you enter <span class=\"st_h\">'.'<\/span>, the field will be left blank.<br \/>\n<span class=\"re5\">-----<\/span><br \/>\nCountry Name <span class=\"br0\">&#40;<\/span><span class=\"nu0\">2<\/span> letter code<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span>FR<span class=\"br0\">&#93;<\/span>:<br \/>\nState or Province Name <span class=\"br0\">&#40;<\/span>full name<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span>NA<span class=\"br0\">&#93;<\/span>:<br \/>\nLocality Name <span class=\"br0\">&#40;<\/span>eg, city<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span>Clichy<span class=\"br0\">&#93;<\/span>:<br \/>\nOrganization Name <span class=\"br0\">&#40;<\/span>eg, company<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span>Whiler.com<span class=\"br0\">&#93;<\/span>:<br \/>\nOrganizational Unit Name <span class=\"br0\">&#40;<\/span>eg, section<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span>Home<span class=\"br0\">&#93;<\/span>:<br \/>\nCommon Name <span class=\"br0\">&#40;<\/span>eg, YOUR name<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span><span class=\"br0\">&#93;<\/span>:Mon client<br \/>\nEmail Address <span class=\"br0\">&#91;<\/span>no_spam<span class=\"sy0\">@<\/span>whiler.com<span class=\"br0\">&#93;<\/span>:<br \/>\n<br \/>\nPlease enter the following <span class=\"st_h\">'extra'<\/span> attributes<br \/>\nto be sent with your certificate request<br \/>\nA challenge password <span class=\"br0\">&#91;<\/span><span class=\"br0\">&#93;<\/span>:To remember<br \/>\nAn optional company name <span class=\"br0\">&#91;<\/span>Whiler.com<span class=\"br0\">&#93;<\/span>:<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw2\">ls<\/span> <span class=\"re5\">-ll<\/span><br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">765<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:04 client.csr<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">963<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:03 client.key<br \/>\n<span class=\"re5\">-rwxr-xr-x<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">9491<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">12<\/span>:<span class=\"nu0\">46<\/span> openssl.cnf<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> Signer le certificat client<br \/>\nSigner le certificat client<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> openssl x509 <span class=\"re5\">-req<\/span> <span class=\"re5\">-days<\/span> <span class=\"nu0\">3650<\/span> <span class=\"re5\">-in<\/span> client.csr <span class=\"re5\">-signkey<\/span> client.key <span class=\"re5\">-out<\/span> client.crt<br \/>\nSignature ok<br \/>\n<span class=\"re2\">subject<\/span>=<span class=\"sy0\">\/<\/span><span class=\"re2\">C<\/span>=FR<span class=\"sy0\">\/<\/span><span class=\"re2\">ST<\/span>=NA<span class=\"sy0\">\/<\/span><span class=\"re2\">L<\/span>=Clichy<span class=\"sy0\">\/<\/span><span class=\"re2\">O<\/span>=Whiler.com<span class=\"sy0\">\/<\/span><span class=\"re2\">OU<\/span>=Home<span class=\"sy0\">\/<\/span><span class=\"re2\">CN<\/span>=Mon client<span class=\"sy0\">\/<\/span><span class=\"re2\">emailAddress<\/span>=no_spam<span class=\"sy0\">@<\/span>whiler.com<br \/>\nGetting Private key<br \/>\nEnter pass phrase <span class=\"kw1\">for<\/span> client.key:<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw2\">ls<\/span> <span class=\"re5\">-ll<\/span><br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">928<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:05 client.crt<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">765<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:04 client.csr<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">963<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:03 client.key<br \/>\n<span class=\"re5\">-rwxr-xr-x<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">9491<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">12<\/span>:<span class=\"nu0\">46<\/span> openssl.cnf<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> CLIENT termin\u00e9<br \/>\nCLIENT termin\u00e9<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> SERVEUR<br \/>\nSERVEUR<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> G\u00e9n\u00e9ration de la cl\u00e9 serveur<br \/>\nG\u00e9n\u00e9ration de la cl\u00e9 serveur<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> openssl genrsa <span class=\"re5\">-des3<\/span> <span class=\"re5\">-out<\/span> serveur.key <span class=\"nu0\">1024<\/span><br \/>\nGenerating RSA private key, <span class=\"nu0\">1024<\/span> bit long modulus<br \/>\n............................++++++<br \/>\n.................++++++<br \/>\ne is <span class=\"nu0\">65537<\/span> <span class=\"br0\">&#40;<\/span>0x10001<span class=\"br0\">&#41;<\/span><br \/>\nEnter pass phrase <span class=\"kw1\">for<\/span> serveur.key:<br \/>\nVerifying - Enter pass phrase <span class=\"kw1\">for<\/span> serveur.key:<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw2\">ls<\/span> <span class=\"re5\">-ll<\/span><br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">928<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:05 client.crt<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">765<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:04 client.csr<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">963<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:03 client.key<br \/>\n<span class=\"re5\">-rwxr-xr-x<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">9491<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">12<\/span>:<span class=\"nu0\">46<\/span> openssl.cnf<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">951<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:07 serveur.key<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> G\u00e9n\u00e9ration <span class=\"kw2\">du<\/span> certificat serveur<br \/>\nG\u00e9n\u00e9ration <span class=\"kw2\">du<\/span> certificat serveur<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> openssl req <span class=\"re5\">-new<\/span> <span class=\"re5\">-key<\/span> serveur.key <span class=\"re5\">-out<\/span> serveur.csr <span class=\"re5\">-config<\/span> <span class=\"sy0\">\/<\/span>usr<span class=\"sy0\">\/<\/span>syno<span class=\"sy0\">\/<\/span>mon_ssl<span class=\"sy0\">\/<\/span>openssl.cnf<br \/>\nEnter pass phrase <span class=\"kw1\">for<\/span> serveur.key:<br \/>\nYou are about to be asked to enter information that will be incorporated<br \/>\ninto your certificate request.<br \/>\nWhat you are about to enter is what is called a Distinguished Name or a DN.<br \/>\nThere are quite a few fields but you can leave some blank<br \/>\nFor some fields there will be a default value,<br \/>\nIf you enter <span class=\"st_h\">'.'<\/span>, the field will be left blank.<br \/>\n<span class=\"re5\">-----<\/span><br \/>\nCountry Name <span class=\"br0\">&#40;<\/span><span class=\"nu0\">2<\/span> letter code<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span>FR<span class=\"br0\">&#93;<\/span>:<br \/>\nState or Province Name <span class=\"br0\">&#40;<\/span>full name<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span>NA<span class=\"br0\">&#93;<\/span>:<br \/>\nLocality Name <span class=\"br0\">&#40;<\/span>eg, city<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span>Clichy<span class=\"br0\">&#93;<\/span>:<br \/>\nOrganization Name <span class=\"br0\">&#40;<\/span>eg, company<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span>Whiler.com<span class=\"br0\">&#93;<\/span>:<br \/>\nOrganizational Unit Name <span class=\"br0\">&#40;<\/span>eg, section<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span>Home<span class=\"br0\">&#93;<\/span>:<br \/>\nCommon Name <span class=\"br0\">&#40;<\/span>eg, YOUR name<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#91;<\/span><span class=\"br0\">&#93;<\/span>:Mon serveur<br \/>\nEmail Address <span class=\"br0\">&#91;<\/span>no_spam<span class=\"sy0\">@<\/span>whiler.com<span class=\"br0\">&#93;<\/span>:<br \/>\n<br \/>\nPlease enter the following <span class=\"st_h\">'extra'<\/span> attributes<br \/>\nto be sent with your certificate request<br \/>\nA challenge password <span class=\"br0\">&#91;<\/span><span class=\"br0\">&#93;<\/span>:<span class=\"nu0\">2<\/span> remember<br \/>\nAn optional company name <span class=\"br0\">&#91;<\/span>Whiler.com<span class=\"br0\">&#93;<\/span>:<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw2\">ls<\/span> <span class=\"re5\">-ll<\/span><br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">928<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:05 client.crt<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">765<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:04 client.csr<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">963<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:03 client.key<br \/>\n<span class=\"re5\">-rwxr-xr-x<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">9491<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">12<\/span>:<span class=\"nu0\">46<\/span> openssl.cnf<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">765<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:08 serveur.csr<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">951<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:07 serveur.key<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> Signer le certificat serveur<br \/>\nSigner le certificat serveur<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> openssl x509 <span class=\"re5\">-req<\/span> <span class=\"re5\">-days<\/span> <span class=\"nu0\">3650<\/span> <span class=\"re5\">-in<\/span> serveur.csr <span class=\"re5\">-CA<\/span> client.crt <span class=\"re5\">-CAkey<\/span> client.key -set_serial 01 <span class=\"re5\">-out<\/span> serveur.crt<br \/>\nSignature ok<br \/>\n<span class=\"re2\">subject<\/span>=<span class=\"sy0\">\/<\/span><span class=\"re2\">C<\/span>=FR<span class=\"sy0\">\/<\/span><span class=\"re2\">ST<\/span>=NA<span class=\"sy0\">\/<\/span><span class=\"re2\">L<\/span>=Clichy<span class=\"sy0\">\/<\/span><span class=\"re2\">O<\/span>=Whiler.com<span class=\"sy0\">\/<\/span><span class=\"re2\">OU<\/span>=Home<span class=\"sy0\">\/<\/span><span class=\"re2\">CN<\/span>=Mon serveur<span class=\"sy0\">\/<\/span><span class=\"re2\">emailAddress<\/span>=no_spam<span class=\"sy0\">@<\/span>whiler.com<br \/>\nGetting CA Private Key<br \/>\nEnter pass phrase <span class=\"kw1\">for<\/span> client.key:<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw2\">ls<\/span> <span class=\"re5\">-ll<\/span><br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">928<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:05 client.crt<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">765<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:04 client.csr<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">963<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:03 client.key<br \/>\n<span class=\"re5\">-rwxr-xr-x<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">9491<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">12<\/span>:<span class=\"nu0\">46<\/span> openssl.cnf<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">916<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:09 serveur.crt<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">765<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:08 serveur.csr<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">951<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:07 serveur.key<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> SERVEUR termin\u00e9<br \/>\nSERVEUR termin\u00e9<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> Cr\u00e9ation d<span class=\"co3\">\\'<\/span>une cl\u00e9 non s\u00e9curis\u00e9e pour Apache<br \/>\nCr\u00e9ation d\u2019une cl\u00e9 non s\u00e9curis\u00e9e pour Apache<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> openssl rsa <span class=\"re5\">-in<\/span> serveur.key <span class=\"re5\">-out<\/span> serveur.key.not_secure<br \/>\nEnter pass phrase <span class=\"kw1\">for<\/span> serveur.key:<br \/>\nwriting RSA key<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw2\">ls<\/span> <span class=\"re5\">-ll<\/span><br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">928<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:05 client.crt<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">765<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:04 client.csr<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">963<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:03 client.key<br \/>\n<span class=\"re5\">-rwxr-xr-x<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class=\"nu0\">9491<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">12<\/span>:<span class=\"nu0\">46<\/span> openssl.cnf<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">916<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:09 serveur.crt<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">765<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:08 serveur.csr<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">951<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:07 serveur.key<br \/>\n<span class=\"re5\">-rw-r--r--<\/span> &nbsp; &nbsp;<span class=\"nu0\">1<\/span> root &nbsp; &nbsp; root &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class=\"nu0\">887<\/span> Feb <span class=\"nu0\">17<\/span> <span class=\"nu0\">13<\/span>:<span class=\"nu0\">11<\/span> serveur.key.not_secure<br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span> <span class=\"kw3\">echo<\/span> FIN : Il ne reste plus qu<span class=\"co3\">\\'<\/span>\u00e0 s<span class=\"co3\">\\'<\/span>en servir <span class=\"sy0\">!<\/span><br \/>\nFIN : Il ne reste plus qu\u2019\u00e0 s\u2019en servir <span class=\"sy0\">!<\/span><br \/>\nDiskStation<span class=\"sy0\">&gt;<\/span><\/div><\/div>\n<p>Cette <a href=\"https:\/\/123adm.free.fr\/home\/pages\/documents\/syno-cert.html\" title=\"Synology : Comment cr\u00e9er ses propres certificats SSL\" target=\"_blank\">page<\/a> m&rsquo;a bien aid\u00e9 \u00e0 comprendre et trouver les lignes n\u00e9cessaires&nbsp;; merci \u00e0 son auteur&nbsp;!  <img src=\"https:\/\/blogs.wittwer.fr\/whiler\/wp-includes\/images\/smilies\/skype\/\/yes.gif\" alt=\"(y)\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\" \/><\/p>\n<div class=\"thanks_button_div\" \n                  style=\"float: right; margin-right: 10px; margin-top:10px;\"><div id=\"thanksButtonDiv_3072_1\" style=\"background-image:url(https:\/\/blogs.wittwer.fr\/whiler\/wp-content\/plugins\/thanks-you-counter-button\/images\/thanks_compact_brown1.png); background-repeat:no-repeat; float: left; display: inline;\"\n                onmouseover=\"javascript:thankYouChangeButtonImage('thanksButtonDiv_3072_1', true);\" \n                onmouseout=\"javascript:thankYouChangeButtonImage('thanksButtonDiv_3072_1', false);\"\n                onclick=\"javascript:thankYouChangeButtonImage('thanksButtonDiv_3072_1', false);\" >\n                <input type=\"button\" onclick=\"thankYouButtonClick(3072, 'You left &ldquo;Thanks&rdquo; already for this post')\" value=\"Merci\u00a0 0\"\n                  class=\"thanks_button thanks_compact thanks_brown1\"\n                  style=\"  font-family: Verdana, Arial, Sans-Serif; font-size: 14px; font-weight: normal;; color:#00f;\"\n                  id=\"thanksButton_3072_1\" title=\"Click to leave &ldquo;Thanks&rdquo; for this post\"\/>\n             <\/div><div id=\"ajax_loader_3072_1\" style=\"display:inline;visibility: hidden;\"><img decoding=\"async\" alt=\"ajax loader\" src=\"https:\/\/blogs.wittwer.fr\/whiler\/wp-content\/plugins\/thanks-you-counter-button\/images\/ajax-loader.gif\" \/><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Sur mon NAS Synology, j\u2019ai OpenSSL qui est install\u00e9\u2026<br \/>\nL\u2019acc\u00e8s n\u2019est pas ouvert en dehors du r\u00e9seau interne, mais j\u2019ai eu envie d\u2019effectuer quelques tests locaux\u2026 alors, je me suis pench\u00e9 sur la g\u00e9n\u00e9ration de certificats\u2026<\/p>\n<p>Afin de pouvoir facilement le refaire ult\u00e9rieurement en cas de besoin, je mets ci-dessous les diff\u00e9rentes lignes de commande que j\u2019ai utilis\u00e9es\u2026<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_links_to":"","_links_to_target":""},"categories":[5],"tags":[27,108],"class_list":["post-3072","post","type-post","status-publish","format-standard","hentry","category-computer","tag-coloration-syntaxique","tag-script"],"_links":{"self":[{"href":"https:\/\/blogs.wittwer.fr\/whiler\/wp-json\/wp\/v2\/posts\/3072","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.wittwer.fr\/whiler\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.wittwer.fr\/whiler\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.wittwer.fr\/whiler\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.wittwer.fr\/whiler\/wp-json\/wp\/v2\/comments?post=3072"}],"version-history":[{"count":0,"href":"https:\/\/blogs.wittwer.fr\/whiler\/wp-json\/wp\/v2\/posts\/3072\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.wittwer.fr\/whiler\/wp-json\/wp\/v2\/media?parent=3072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.wittwer.fr\/whiler\/wp-json\/wp\/v2\/categories?post=3072"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.wittwer.fr\/whiler\/wp-json\/wp\/v2\/tags?post=3072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}