#!/bin/sh
# generate CA private key
openssl ecparam -out contoso.key -name prime256v1 -genkey
# generate CA cert, with common name: www.contoso.com
openssl req -new -sha256 -key contoso.key -out contoso.csr
# generate CA root cert
openssl x509 -req -sha256 -days 365 -in contoso.csr -signkey contoso.key -out contoso.crt
# generate server private key
openssl ecparam -out fabrikam.key -name prime256v1 -genkey
# generate server safe cert request
openssl req -new -sha256 -key fabrikam.key -out fabrikam.csr
# generate server safe cert
openssl x509 -req -in fabrikam.csr -CA contoso.crt -CAkey contoso.key -CAcreateserial -out fabrikam.crt -days 365 -sha256