...
pkcs11-tool --module /usr/lib64/librtpkcs11ecp.so --keypairgen --key-type rsa:2048 -l --id 45
|
...
$ OPENSSL_CONF= /path/to/engine .conf openssl req -engine pkcs11 -x509 -new -key 0:45 -keyform engine -out cert.crt -subj "/C=RU/ST=Moscow/L=Moscow/O=Aktiv/OU=dev/CN=testuser/emailAddress=testuser@mail.com" OPENSSL_CONF=/home/user/Загрузки/engine.conf openssl req -engine pkcs11 -x509 -new -key 0:45 -keyform engine -out cert.crt -subj "/СN=test/C=RU/ST=Moscow/L=Moscow/O=Aktiv/OU=dev/emailAddress= testuser@mailtestuser@mail.com"
|
Сохраните сертификат на токене:
...