How To Create Self Signed Root Certificate with OpenSSL


OpenSSL provides cryptographic libraries and features. We can use OpenSSL from reading DER files to generate random numbers. But one of the most used feature is creating a Self Signed Certificate. ,

Self Signed Certificate

X509 is the certificate standard used in internet and corporate today. X509 certificates are designed to create a tree like trust hierarchy between X509 certificates. For example Google is a trusted entity and is another entity trusted by Google so we created a chain with this trust relationship. But as we see there is always a root. Self signed certificates are not signed by other certificates which means they may be used as root certificate or as standalone.

Create Self Signed Certificate

We can create a self signed X509 certificate by using OpenSSL req verb. Other options are

  • Algorithm is RSA
  • Key size is 4096 bit
  • Format is PEM
  • Until valid 365 days

Create Self Signed Certificate

Create Self Signed Certificate

Create Self Signed Certificate without Encrypting

In previous step we will be asked for the password with the following phrase

We can prevent the encrytion of the created Self signed certificate with the -node option like below.

Self Signed Certificate Errors and Warnings

As stated before self signed certificates to not enter a trust relationship with other certificates. This is generally creates some errors and warnings especially by browsers. Browsers uses Certificate Authorities Root Certificates to check trust of the provided certificate. Because self signed certificate is not signed by any of them browser will show a warning message .

LEARN MORE  How To Generate Random Numbers and Password with OpenSSL Rand

You may also like...

Leave a Reply

Your email address will not be published.

Enjoy this blog? Please spread the word :)