openssl genrsa -out server.key 2048
openssl rsa -in server.key -pubout -out server.pem
openssl genrsa -out ca.key 2048
openssl req -new -key ca.key -out ca.csr -subj
"/C=CN/ST=myprovince/L=mycity/O=myorganization/OU=mygroup/CN=myname"
openssl x509 -req -in ca.csr -signkey ca.key -out ca.crt -days 36500
openssl req -new -key server.key -out server.csr
openssl req -new -key server.key -out server.csr -subj
"/C=CN/ST=myprovince/L=mycity/O=myorganization/OU=mygroup/CN=myname"
//Common Name (e.g. server FQDN or YOUR name) []:localhost
openssl x509 -req -CA ca.crt -CAkey ca.key -CAcreateserial -in server.csr -out server.crt -days 36500
转载自:https://blog.51cto.com/14043491/2337321