在192.168.1.102上操作

touch /etc/pki/CA/index.txt


echo 01 > /etc/pki/CA/serial


(umask 077; openssl genrsa -out/etc/pki/CA/private/cakey.pem 2048)


openssl req -new -x509 -key /etc/pki/CA/private/cakey.pem -days 7300 -out /etc/pki/CA/cacert.pem

从零开始部署httpd2.2之二 创建CA