General OpenSSL Commands
### Fast self-signed KEY and CRT
openssl genrsa -out 172.25.25.12.key 2048
openssl req -new -x509 -key 172.25.25.12.key -out 172.25.25.12.cert -days 3560 -subj /CN=172.25.25.12
### How to create a self-signed certificate with openssl?
openssl genrsa -des3 -out server.key 2048
openssl rsa -in server.key -out server.key
openssl req -sha256 -new -key server.key -out server.csr -subj '/CN=localhost'
openssl x509 -req -sha256 -days 365 -in server.csr -signkey server.key -out server.crt
Replace 'localhost' with whatever domain you require. You will need to run the first two commands one by one as openssl will prompt for a passphrase.
### To combine the two into a .pem file:
cat server.crt server.key > cert.pem
### Converting Using OpenSSL
### Convert a DER file (.crt .cer .der) to PEM
openssl x509 -inform der -in certificate.cer -out certificate.pem
### Convert a PEM file to DER
openssl x509 -outform der -in certificate.pem -out certificate.der
### Convert a PKCS#12 file (.pfx .p12) containing a private key and certificates to PEM
openssl pkcs12 -in keyStore.pfx -out keyStore.pem -nodes
You can add -nocerts to only output the private key or add -nokeys to only output the certificates.
### Convert a PEM certificate file and a private key to PKCS#12 (.pfx .p12)
openssl pkcs12 -export -out certificate.pfx -inkey privateKey.key -in certificate.crt -certfile CACert.crt