blob: 7a24a4ffa034f7f8c576715faa5e858f66037966 [file] [log] [blame]
Jean-Paul Calderone897bc252008-02-18 20:50:23 -05001"""
2Create certificates and private keys for the 'simple' example.
3"""
4
5from OpenSSL import crypto
6from certgen import * # yes yes, I know, I'm lazy
Jim Shaver4ca59a12015-04-25 17:31:22 -04007cakey = createKeyPair(TYPE_RSA, 2048)
Jean-Paul Calderone897bc252008-02-18 20:50:23 -05008careq = createCertRequest(cakey, CN='Certificate Authority')
9cacert = createCertificate(careq, (careq, cakey), 0, (0, 60*60*24*365*5)) # five years
Jim Shaver05298862015-04-29 01:09:13 -040010
Jim Shaver6b5d3812015-04-25 17:45:53 -040011print('Creating Certificate Authority private key in "simple/CA.pkey"')
Jim Shaver05298862015-04-29 01:09:13 -040012open('simple/CA.pkey', 'w').write(crypto.dump_privatekey(crypto.FILETYPE_PEM, cakey).decode('utf-8'))
Jim Shaver6b5d3812015-04-25 17:45:53 -040013print('Creating Certificate Authority certificate in "simple/CA.cert"')
Jim Shaver05298862015-04-29 01:09:13 -040014open('simple/CA.cert', 'w').write(crypto.dump_certificate(crypto.FILETYPE_PEM, cacert).decode('utf-8'))
15
Jean-Paul Calderone897bc252008-02-18 20:50:23 -050016for (fname, cname) in [('client', 'Simple Client'), ('server', 'Simple Server')]:
Jim Shaver4ca59a12015-04-25 17:31:22 -040017 pkey = createKeyPair(TYPE_RSA, 2048)
Jean-Paul Calderone897bc252008-02-18 20:50:23 -050018 req = createCertRequest(pkey, CN=cname)
19 cert = createCertificate(req, (cacert, cakey), 1, (0, 60*60*24*365*5)) # five years
Jim Shaver05298862015-04-29 01:09:13 -040020
Jim Shaver6b5d3812015-04-25 17:45:53 -040021 print('Creating Certificate %s private key in "simple/%s.pkey"' % (fname, fname))
Jim Shaver05298862015-04-29 01:09:13 -040022 open('simple/%s.pkey' % (fname,), 'w').write(crypto.dump_privatekey(crypto.FILETYPE_PEM, pkey).decode('utf-8'))
Jim Shaver6b5d3812015-04-25 17:45:53 -040023 print('Creating Certificate %s certificate in "simple/%s.cert"' % (fname, fname))
Jim Shaver05298862015-04-29 01:09:13 -040024 open('simple/%s.cert' % (fname,), 'w').write(crypto.dump_certificate(crypto.FILETYPE_PEM, cert).decode('utf-8'))