mirror of
https://github.com/Start9Labs/start-os.git
synced 2026-03-31 04:23:40 +00:00
attempt to use P256 instead
This commit is contained in:
@@ -306,7 +306,7 @@ writeIntermediateCert :: MonadIO m => DeriveCertificate -> m (ExitCode, String,
|
|||||||
writeIntermediateCert DeriveCertificate {..} = liftIO $ fromSys $ interpret $ do
|
writeIntermediateCert DeriveCertificate {..} = liftIO $ fromSys $ interpret $ do
|
||||||
lift . lift $ time "Intermediate Cert Write Start"
|
lift . lift $ time "Intermediate Cert Write Start"
|
||||||
-- openssl genrsa -out dump/int.key 4096
|
-- openssl genrsa -out dump/int.key 4096
|
||||||
segment $ openssl [i|genrsa -out #{applicantKeyPath} 4096|]
|
segment $ openssl [i|ecparam -genkey -name prime256v1 -noout -out #{applicantKeyPath}|]
|
||||||
lift . lift $ time "Generate intermediate RSA Key"
|
lift . lift $ time "Generate intermediate RSA Key"
|
||||||
-- openssl req -new -config dump/int-csr.conf -key dump/int.key -nodes -out dump/int.csr
|
-- openssl req -new -config dump/int-csr.conf -key dump/int.key -nodes -out dump/int.csr
|
||||||
segment $ openssl [i|req -new
|
segment $ openssl [i|req -new
|
||||||
@@ -333,7 +333,7 @@ writeIntermediateCert DeriveCertificate {..} = liftIO $ fromSys $ interpret $ do
|
|||||||
writeLeafCert :: MonadIO m => DeriveCertificate -> Text -> Text -> m (ExitCode, String, String)
|
writeLeafCert :: MonadIO m => DeriveCertificate -> Text -> Text -> m (ExitCode, String, String)
|
||||||
writeLeafCert DeriveCertificate {..} hostname torAddress = liftIO $ fromSys $ interpret $ do
|
writeLeafCert DeriveCertificate {..} hostname torAddress = liftIO $ fromSys $ interpret $ do
|
||||||
lift . lift $ time "Leaf Cert Write Start"
|
lift . lift $ time "Leaf Cert Write Start"
|
||||||
segment $ openssl [i|genrsa -out #{applicantKeyPath} 4096|]
|
segment $ openssl [i|ecparam -genkey -name prime256v1 -noout -out #{applicantKeyPath}|]
|
||||||
lift . lift $ time "Generate leaf RSA Key"
|
lift . lift $ time "Generate leaf RSA Key"
|
||||||
segment $ openssl [i|req -config #{applicantConfPath}
|
segment $ openssl [i|req -config #{applicantConfPath}
|
||||||
-key #{applicantKeyPath}
|
-key #{applicantKeyPath}
|
||||||
|
|||||||
Reference in New Issue
Block a user