cfssl gencert -initca ca-csr.json | cfssljson -bare ca -
cfssl genkey server.json | cfssljson -bare server
cfssl sign -config=ca-config.json -profile=server -csr=server.csr -ca=ca.pem -ca-key=ca-key.pem | cfssljson -bare server
cfssl gencert -ca=ca.pem -ca-key=ca-key.pem -config=ca-config.json -profile=client client.json | cfssljson -bare client
openssl rsa -in ca-key.pem -text
openssl x509 -in ca.pem -text
openssl x509 -in ca.pem -inform PEM -out ca.crt -outform DER
openssl pkcs12 -export -out client-key.pfx -inkey client-key.pem -in client.pem
- Do not issue certificates for 'localhost'.
- Do not issue certificates for '127.0.0.1'.