Creating a cert
-
Construct a requirement config and save the file as "req.conf".
[req] distinguished_name = req_distinguished_name x509_extensions = v3_req prompt = no [req_distinguished_name] C = MY ST = Kuala Lumpur L = Kuala Lumpur O = Company Name CN = localhost [v3_req] keyUsage = digitalSignature, keyEncipherment, dataEncipherment extendedKeyUsage = serverAuth subjectAltName = @alt_names [alt_names] DNS.1 = localhost.abc DNS.2 = localhost -
It is important to include "digitalSignature" in the keyUsage field, otherwise modern browsers would block the cert.
-
Run the following OpenSSL command to generate the certificate. Replace the "days" value as needed.
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout key.pem -out certificate.pem -config req.conf -extensions 'v3_req' -
Run the following OpenSSL command to get the P12 format.
openssl pkcs12 -inkey key.pem -in certificate.pem -export -out certificate.p12If this certificate is also used on older system (E.g. Windows 7), please include the -legacy option.
openssl pkcs12 -legacy -inkey key.pem -in certificate.pem -export -out certificate.p12 -
Or if you need a JKS format.
keytool -importkeystore -srckeystore certificate.p12 -srcstoretype pkcs12 -destkeystore certificate.jks -deststoretype jks
Install Cert on MacOS
-
Go to the "Keychain Access" App on your device.
-
Select "Files", then "Import Items".
-
Select the cert file that you created earlier.
-
Double clicks on the imported cert and expand the trust section

-
Set it to "Always Trust".
-
Now you can try to access the HTTPS URL from your browser, and it should be trusted.