0Pricing
Cryptology Academy · Lesson

Creating Self-Signed Certs with OpenSSL

Generate your own CA, sign a certificate, and inspect it with OpenSSL.

Creating Self-Signed Certs with OpenSSL is a free Cryptology Academy lesson on CoddyKit — lesson 4 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cryptology Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Welcome

In this hands-on lesson we create our own mini CA with OpenSSL, sign a server certificate, and inspect every field — learning PKI from the inside out.

Generate the Root CA Key

# Generate 4096-bit RSA CA private key openssl genrsa -aes256 -out ca.key 4096 The -aes256 flag encrypts the private key with a passphrase. Always protect CA keys.

Create the Root CA Certificate

openssl req -x509 -new -nodes -key ca.key \ -sha256 -days 3650 \ -out ca.crt \ -subj '/C=US/O=My CA/CN=My Root CA' -x509 makes it self-signed. -days 3650 = 10 years.

Generate the Server Key

# Generate 2048-bit RSA server key (no passphrase for web servers) openssl genrsa -out server.key 2048 Server keys should not have passphrases (web servers can't prompt during startup).

Create a Certificate Signing Request (CSR)

openssl req -new -key server.key \ -out server.csr \ -subj '/C=US/O=My App/CN=localhost' The CSR contains the public key and requested subject. It is signed by the applicant's private key.

Create SAN Extension File

cat > server.ext <

Sign the Server Certificate

openssl x509 -req \ -in server.csr \ -CA ca.crt -CAkey ca.key \ -CAcreateserial \ -out server.crt \ -days 365 -sha256 \ -extfile server.ext

Inspect the Certificate

openssl x509 -in server.crt -text -noout Look for: Issuer, Subject, Not Before/After, Subject Alternative Name, Key Usage, and the Signature Algorithm at the bottom.

Verify the Chain

openssl verify -CAfile ca.crt server.crt # server.crt: OK This confirms the server certificate was correctly signed by our CA. Any modification to the cert would fail verification.

Test with curl

# Start a Python server with the cert: # python3 -m http.server --bind 127.0.0.1 8443 # (simplified) # Test with our CA cert: curl --cacert ca.crt https://localhost:8443 # Without --cacert, curl would reject the self-signed CA

Exporting to PKCS12

PKCS12 bundles the certificate, private key, and CA chain in one file: openssl pkcs12 -export \ -in server.crt -inkey server.key \ -certfile ca.crt \ -out server.p12 Used by Java keystores and Windows certificate stores.

Quick Check

What OpenSSL command creates a self-signed root CA certificate from a private key?

Recap

Excellent! You've built a complete PKI from scratch. Next we study password hashing — why SHA-256 is wrong for passwords and what bcrypt/Argon2 do differently.

Frequently asked questions

Is the “Creating Self-Signed Certs with OpenSSL” lesson free?

Yes — the full text of “Creating Self-Signed Certs with OpenSSL” is free to read here on the web, and the Cryptology Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cryptology Academy course, upgrade to CoddyKit PRO.

What will I learn in “Creating Self-Signed Certs with OpenSSL”?

Generate your own CA, sign a certificate, and inspect it with OpenSSL. You practise Cryptology Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Cryptology Academy?

No prior experience is required. Cryptology Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 4 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “Creating Self-Signed Certs with OpenSSL” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Cryptology Academy lesson?

Yes. Every Cryptology Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. What Is a Certificate? X.509 Structure
  2. Certificate Authorities & Trust Chains
  3. Certificate Revocation: CRL & OCSP
  4. Creating Self-Signed Certs with OpenSSL
← Back to Cryptology Academy