Certificados SSL y Java Keystores
Este post sirve para generar CSR, revisar certificados, convertir formatos, gestionar keystores Java y validar firmas de JAR.
Crear clave y CSR con OpenSSL
1
2
| openssl genrsa -out app.example.local.key 4096
openssl req -new -sha256 -key app.example.local.key -out app.example.local.csr
|
Certificado autofirmado con SAN
1
2
3
4
5
6
| openssl req -x509 -nodes -newkey rsa:4096 \
-keyout app.example.local.key \
-out app.example.local.crt \
-days 365 \
-subj "/CN=app.example.local" \
-addext "subjectAltName=DNS:app.example.local,DNS:alias.example.local"
|
Ver contenido de certificado
1
2
3
| openssl x509 -in app.example.local.crt -noout -text
openssl x509 -in app.example.local.crt -noout -dates
openssl x509 -in app.example.local.crt -noout -issuer -subject
|
Comprobar certificado remoto
1
| openssl s_client -connect app.example.local:443 -servername app.example.local </dev/null
|
Convertir PEM a PKCS12
1
2
3
4
5
| openssl pkcs12 -export \
-in app.example.local.crt \
-inkey app.example.local.key \
-out app.example.local.p12 \
-name app
|
Importar en JKS
1
2
3
4
5
| keytool -importkeystore \
-srckeystore app.example.local.p12 \
-srcstoretype PKCS12 \
-destkeystore app.jks \
-deststoretype JKS
|
Listar JKS
1
| keytool -list -v -keystore app.jks
|
Importar CA en truststore
1
2
3
4
| keytool -importcert \
-alias ca-example \
-file ca-example.crt \
-keystore truststore.jks
|
Firmar JAR
1
2
| jarsigner -keystore app.jks aplicacion.jar app
jarsigner -verify -verbose -certs aplicacion.jar
|
Renovacion de certificado
1
2
3
| openssl x509 -in app.example.local.crt -noout -dates
keytool -list -v -keystore app.jks | grep -E 'Alias name|Valid from'
systemctl reload httpd
|
Certbot con Apache
1
2
3
| apt install -y certbot python3-certbot-apache
certbot --apache -d app.example.local -m usuario@example.com --agree-tos
certbot renew --dry-run
|
Scripts relacionados
libra_scripts documenta renovacion wildcard con certbot --dns-cloudflare, copia controlada de PEMs e importacion de certificados en pfSense/HAProxy.
DNS-01 con Cloudflare
1
2
3
4
5
6
| certbot certonly \
--dns-cloudflare \
--dns-cloudflare-credentials /ruta/segura/cloudflare.ini \
--non-interactive \
-d example.net \
-d '*.example.net'
|
El fichero de credenciales debe tener permisos restrictivos:
1
| chmod 600 /ruta/segura/cloudflare.ini
|