<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>viaVerio :: Creating a CSR and PK</title>
	<copyright>Copyright (c) 2007 Verio Inc. All rights reserved.</copyright>
    <link>http://www.viaverio.com/index.cfm?page_id=559</link>
    <description>Creating a CSR and PK</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 06 Nov 2007 15:46:57 GMT</lastBuildDate>
	<managingEditor>sales@verio.net</managingEditor>
	<webMaster>sales@verio.net</webMaster>
	<ttl>5</ttl>	
    <image>
      <title>viaVerio :: Creating a CSR and PK</title>
	  <width>149</width>
	  <height>70</height>
	  <link>http://www.viaverio.com</link>
      <url>http://www.viaverio.com/images2/nav/viaverio_logo.gif</url>
    </image>
	<item>
	  <title>Creating a CSR and PK</title>
	  <link>http://www.viaverio.com/rss/page_559.rss</link>
	  <guid isPermaLink="true">http://www.viaverio.com/rss/page_559.rss</guid>
	  <pubDate>Wed, 13 Oct 2004 12:00:00 GMT</pubDate>
	  <description>
	    <![CDATA[ &lt;h1&gt;Creating a Certificate Signing Request and Private Key&lt;/h1&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;In order to obtain a signed Digital Certificate, you must create a Certificate Signing Request, or CSR.  At the same time your&lt;br&gt;	CSR is created, you will also generate a Private Key.  The CSR is used by the Signing Authority to create a Signed Digital&lt;br&gt;	Certificate which works with your Private Key to provide secure access to your Web site.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;There is some information that you will need to gather before generating the CSR and Private Key.  This information is&lt;br&gt;	required as part of the CSR, and must be entered exactly as you want them to appear in your certificate.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;ul&gt;&lt;br&gt;&lt;li&gt;&lt;h3&gt;PEM Passphrase&lt;/h3&gt;&lt;br&gt;			&lt;br&gt;		&lt;br&gt;&lt;p&gt;This is a security phrase which, like a password, ensures that only you can use your digital certificate.  Be sure to&lt;br&gt;			use a phrase which you can easily remember but which is not easily guessed.  You will need to enter the passphrase in the&lt;br&gt;			future to install your signed certificate.&lt;/p&gt; &lt;/li&gt;&lt;br&gt;		&lt;br&gt;&lt;li&gt;&lt;h3&gt;Company Location&lt;/h3&gt;&lt;br&gt;			&lt;br&gt;		&lt;br&gt;&lt;p&gt;You will need to know the country, province or state, and city where you want the certificate to display as your&lt;br&gt;			company location.&lt;/p&gt; &lt;/li&gt;&lt;br&gt;		&lt;br&gt;&lt;li&gt;&lt;h3&gt;Company Contact Information&lt;/h3&gt;&lt;br&gt;			&lt;br&gt;		&lt;br&gt;&lt;p&gt;This includes the complete company or organization name, and the organizational unit or department (if&lt;br&gt;			applicable).&lt;/p&gt; &lt;/li&gt;&lt;br&gt;		&lt;br&gt;&lt;li&gt;&lt;h3&gt;Your Domain Name&lt;/h3&gt;&lt;br&gt;			&lt;br&gt;		&lt;br&gt;&lt;p&gt;You will need to determine the &lt;b&gt;exact&lt;/b&gt; domain name that you want to use to access your Web site securely.&lt;/p&gt; &lt;/li&gt;&lt;br&gt;		&lt;br&gt;&lt;li&gt;&lt;h3&gt;Contact E-mail Address&lt;/h3&gt;&lt;br&gt;			&lt;br&gt;		&lt;br&gt;&lt;p&gt;The contact E-mail address that you want to have the Signing Authority use when corresponding with you.&lt;/p&gt; &lt;/li&gt;&lt;br&gt;		&lt;br&gt;&lt;li&gt;&lt;h3&gt;Extra Information&lt;/h3&gt;&lt;br&gt;			&lt;br&gt;		&lt;br&gt;&lt;p&gt;This is additional information that is not required, but may be useful.  It includes a challenge password, which some&lt;br&gt;			Signing Authorities use to allow you access to your certificate and which they may require when interacting with&lt;br&gt;			them.  You can also enter additional company information.&lt;/p&gt; &lt;/li&gt;&lt;br&gt;&lt;/ul&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;Once you have all the information ready to enter, connect to you Virtual Private Server via &lt;br&gt;	&lt;a href=&quot;/index.cfm?page_id=426&quot;&gt;SSH or Telnet&lt;/a&gt; and run the following command.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;blockquote&gt;&lt;br&gt;		&lt;pre&gt;% openssl req -new&lt;/pre&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;You will be asked to provide the information you gathered earlier.  Most of the questions are self explanatory, except that&lt;br&gt;	&lt;i&gt;common name&lt;/i&gt; refers to the domain name that you want to use when accessing your site using SSL (ie &lt;i&gt;domain.com&lt;/i&gt; or&lt;br&gt;	&lt;i&gt;www.domain.com&lt;/i&gt; or &lt;i&gt;cname.domain.com&lt;/i&gt; or &lt;i&gt;*.domain.com&lt;/i&gt;).&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;When you have entered all the data, your CSR will be shown.  It is a good idea to save the CSR by copying and pasting it into&lt;br&gt;	a file on your local computer.  You will need it when you are ordering your SSL certificate from the Signing Authority&apos;s Web&lt;br&gt;	site.  The following is an example of a CSR.  Note that the CSR includes the lines with &lt;i&gt;BEGIN CERTIFICATE REQUEST&lt;/i&gt; &lt;br&gt;	and &lt;i&gt;END CERTIFICATE REQUEST&lt;/i&gt;.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;blockquote&gt;&lt;br&gt;		&lt;pre&gt;-----BEGIN CERTIFICATE REQUEST-----&lt;br&gt;MIIB2jCCAUMCAQAwgYExCzAJBgNVBAYTAlVTMQ0wCwYDVQQIEwRVdGFoMQ4wDAYD&lt;br&gt;VQQHEwVQcm92bzETMBEGA1UEChMKU3R1bmt3b3JrczEVMBMGA1UEAxMMTWFyayBT&lt;br&gt;cGVuY2VyMScwJQYJKoZIhvcNAQkBFhh3ZWJtYXN0ZXJAc3R1bmt3b3Jrcy5jb20w&lt;br&gt;gZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAKIkMHnII4uNDwgTYsBYdiiOBLTY&lt;br&gt;NOsTfXp/5sG1VXjlYhDMoLzWxBbaulx2hEufj1Sfkm65Mrd8j4nMFVIGf1sGnFCj&lt;br&gt;ClgxQ/5DJtV22jgnqQfKq7se32r9INoPWjFfjD1JC+4zry5LRiSPNImCYq2E1578&lt;br&gt;h6S6i6auD1nTDD0LAgMBAAGgGDAWBgkqhkiG9w0BCQcxCRMHZ3JvYmxpbjANBgkq&lt;br&gt;hkiG9w0BAQQFAAOBgQANwQ7wudkfkxrrZA4lXbOYeXWLngHtNdzPJ8WyzOjGof4h&lt;br&gt;jkpDPV6SJqHEszpmZljEqb6fxgeiM4cpWSFGJA1QNFz+Ra8/msrLLBMM+zPuHpER&lt;br&gt;OPFCsrIErmaBgnmymGOk/DiHvhV+LqCkAgjcS2Kpn0cOy8KRyXzUc4k+TTw0Uw==&lt;br&gt;-----END CERTIFICATE REQUEST-----&lt;/pre&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;In the directory where you were when you ran the &lt;i&gt;openssl&lt;/i&gt; command, you will also find a new file called&lt;br&gt;	&lt;i&gt;privkey.pm&lt;/i&gt;.  This is your private key, which you will need at a later time.  The following is an example of a private key. &lt;br&gt;	Note that the lines containing &lt;i&gt;BEGIN RSA PRIVATE KEY&lt;/i&gt; and &lt;i&gt;END RSA PRIVATE KEY&lt;/i&gt; are part of the key.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;blockquote&gt;&lt;br&gt;		&lt;pre&gt;-----BEGIN RSA PRIVATE KEY-----&lt;br&gt;Proc-Type: 4,ENCRYPTED&lt;br&gt;DEK-Info: DES-EDE3-CBC,BCC23A5E16582F3D&lt;br&gt;&lt;br&gt;hfWyPkea3gnVCHCZJ/zgQpCH9RZF7WjYXGYohdbfkJY0ETLwXaqjvnNHQlLomwIt&lt;br&gt;CvAzXhq8wnHur6SK21SO0ry3aSCvrBezH99miSJvtnT0HVlRJDNvaYQDbe01Z26D&lt;br&gt;hY2Yqha56Z8pvrTTolJfNL0sW4ewdws1wR4kxYDYkpusoe/Wed9Wg+i6xr9YmIjT&lt;br&gt;le9bbQlPK2D/3gJDhWW/aZHiMmLcYJtmWmf0wUMdmlibWYuq0UH1EefiLq3SLKK2&lt;br&gt;izvYpWDGHxVgtmzupvoc2E6CS3rQeRN3QQ9RqhzqdGqP8Xy/xl1LMuDRUbPY54Kp&lt;br&gt;3a4gqZCXdlxctK70XX5TdhiMsFEb5L1wA8CsnKE69nzs8MOLiz6mjtAhGB6KVKB4&lt;br&gt;dod3Wn6z20cus21SY5LxFkfq6JZrAsqSZFzETN9n2Fbel2pTp3IRWx7Q+WBTlrME&lt;br&gt;uIMgUSKszpvgzg0Tf2Kxfw6YWl5EpEGA8PeiGrM1NeT2TFtgiQBRQdAy7TQxgBlF&lt;br&gt;LOW2r5/1347ZgafacXLzpDBHnQrn/OtZijzleeoIwcgVwCOKz1oufEAN1ZTJbG6F&lt;br&gt;WYJuFtfopM5swyoUYK3JgT582ziAeu4jcPdrNHCxqcInkNG+ib3dHdy8yccWRehD&lt;br&gt;VnSX2hr1MDd2cpFFTl77Bc2/neNyUieqiHkrTOZIcD9oBSxFd0fP9QxLWEMCDWHt&lt;br&gt;N5UK1n29+TFgm/aXjZNjSIE5DSjTTBGTy2fPWtnefQaFk23ppV5VQypmZjxcWt2f&lt;br&gt;Eekjh1vEiQChKULQCXFAaxL61HvBRqe3iJwJ+niOBuGpYnjdC80oIA==&lt;br&gt;-----END RSA PRIVATE KEY-----&lt;/pre&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;Once you have your CSR and Private Key, the next step is to &lt;a href=&quot;/index.cfm?page_id=567&quot;&gt;Obtain&lt;br&gt;	your signed Digital Certificate&lt;/a&gt;.&lt;/p&gt;]]>
	  </description>
	  <author>Content V1</author>
	</item>
  </channel>
</rss> 
