创建自己的CA机构
1. 创建 openssl.cnf [ ca ] default_ca = subchen_ca [ subchen_ca ] certificate = ./ca-cert.pem private_key = ./ca-key.pem database = ./index.txt serial = ./serial new_certs_dir = ./certs default_days = 3650 default_md = sha1 policy = subchen_ca_policy x509_extensions = subchen_ca_extensions [ subchen_ca_policy ] commonName = supplied stateOrProvinceName = optional countryName = optional emailAddress = optional organizationName = optional organizationalUnitName = optional [ subchen_ca_extensions ] basicConstraints = CA:false [ req ] default_bits = 2048 default_keyfile = ./ca-key.pem default_md =