ad489b78e39d074d137336cb87daee94532fe19f
[x509-shell-scripts] / user-certificate.sh
1 cd /etc/strongswan/ipsec.d/
2 strongswan pki --gen --type rsa --size 2048 \
3         --outform pem \
4         > private/RobKey.pem
5 chmod 600 private/RobKey.pem
6 strongswan pki --pub --in private/RobKey.pem --type rsa | \
7         strongswan pki --issue --lifetime 730 \
8         --cacert cacerts/strongswanCert.pem \
9         --cakey private/strongswanKey.pem \
10         --dn "C=JP, O=ROB-VPN-JP, CN=rakrens@gmail.com" \
11         --san rakrens@gmail.com \
12         --outform pem > certs/RobCert.pem