{"id":407,"date":"2023-09-06T09:51:01","date_gmt":"2023-09-06T07:51:01","guid":{"rendered":"https:\/\/whoami.lausitz-event.info\/?p=407"},"modified":"2023-09-06T09:57:13","modified_gmt":"2023-09-06T07:57:13","slug":"handling-mit-zertifikaten","status":"publish","type":"post","link":"https:\/\/whoami.lausitz-event.info\/?p=407","title":{"rendered":"Handling mit Zertifikaten"},"content":{"rendered":"\n\n<p>Will man Zertifikaten verwenden, so muss erst ein sogenannter Zertifikatsrequest erstellt werden. Daf\u00fcr legt man eine Datei mit den Spezifikationen des Zertifikats an.<\/p>\n\n\n\n\n\n<p><strong>\/etc\/ssl\/req.conf<\/strong><\/p>\n\n\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;req]\ndistinguished_name = req_distinguished_name\nreq_extensions = v3_req\nprompt = no\n&#91;req_distinguished_name]\nC = DE\nST = Bundesland\nL = Stadt\nO = Organisation\nOU = IT-Abteilung\nCN = go.domain.de\n&#91;v3_req]\nkeyUsage = keyEncipherment, dataEncipherment\nextendedKeyUsage = serverAuth\nsubjectAltName = @alt_names\n&#91;alt_names]\nDNS.1 = test1.domain.de\nDNS.2 = go.domain.de.de\nDNS.3 = test2.domain.de<\/code><\/pre>\n\n\n\n\n\n<p>Ist das erledigt, erstellt man mit openssl einen Zertifikatsrequest.<\/p>\n\n\n\n\n\n<pre class=\"wp-block-code\"><code>openssl req -new -out domain.de.csr -key domain.de.key -config req.conf\n<\/code><\/pre>\n\n\n\n\n\n<p>Die entstandene CSR schickt man dann seinem Zertifikatsanbieter. Dieser stellt dann das offizielle Zertifikat aus und sendet dieses in den unterschiedlichsten Formaten als ZIP Datei zur\u00fcck. Viele Ger\u00e4te, unter anderem FortiGate oder auch die Cisco ASA ben\u00f6tigen ein Zertifikat in dem Format PKCS12. Das enthaltene Zertifikat mit der Endung *.crt muss demzufolge umgewandelt werden. Das  macht man ganz entspannt mit dem Tool <a href=\"https:\/\/github.com\/chris2511\/xca\/releases\/tag\/RELEASE.2.4.0\">XCA<\/a>. Dazu einfach eine neue Datenbank anlegen -&gt; Private Key importieren -&gt; Zertifikat *.crt importieren und dann das Zertifikat als PKCS12 exportieren.<\/p>\n\n\n\n\n\n<p>Fertig!<\/p>\n\n\n","protected":false},"excerpt":{"rendered":"<p>Will man Zertifikaten verwenden, so muss erst ein sogenannter Zertifikatsrequest erstellt werden. Daf\u00fcr legt man eine Datei mit den Spezifikationen des Zertifikats an. \/etc\/ssl\/req.conf Ist das erledigt, erstellt man mit openssl einen Zertifikatsrequest. Die entstandene CSR schickt man dann seinem Zertifikatsanbieter. Dieser stellt dann das offizielle Zertifikat aus und sendet dieses in den unterschiedlichsten Formaten [&hellip;]<\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[3,12],"tags":[],"class_list":["post-407","post","type-post","status-publish","format-standard","hentry","category-it","category-linux"],"_links":{"self":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts\/407","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=407"}],"version-history":[{"count":4,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts\/407\/revisions"}],"predecessor-version":[{"id":412,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts\/407\/revisions\/412"}],"wp:attachment":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=407"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=407"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=407"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}