Run an internal CA, issue a TLS certificate, and refuse old protocols
Task
Create a small internal certificate authority with OpenSSL, issue a server certificate for web.lab.internal with the right subject alternative name, configure nginx to serve it with TLS 1.2 and 1.3 only, and prove from a client that the certificate validates against your CA, that old protocols are refused, and how many days remain before it expires.
Steps
- On lin-srv, create a CA private key and a self-signed CA certificate valid for five years. Create a server key and a certificate signing request, and sign it with the CA for 397 days, with
subjectAltName=DNS:web.lab.internal. Saveopenssl x509 -text -nooutof the server certificate tolab/tls/server-cert.txt. - Configure nginx on port 443 with the server certificate and key and
ssl_protocols TLSv1.2 TLSv1.3;. Save the server block tolab/tls/nginx.txt. - Copy the CA certificate to the client. Run
openssl s_client -connect web.lab.internal:443 -servername web.lab.internal -CAfile ca.crtand save the output tolab/tls/verify.txt. - Try TLS 1.1 with
openssl s_client -connect web.lab.internal:443 -tls1_1 -cipher 'DEFAULT:@SECLEVEL=0'and save the output tolab/tls/old-protocol.txt. The-cipheroption lowers the client's own security level: OpenSSL 3 will not offer TLS 1.1 at its default, so without it the attempt fails against any server, hardened or not, and proves nothing about nginx. - Write
lab/tls/expiry.shthat prints the number of days until a certificate file expires, run it on the server certificate, and save the output tolab/tls/expiry.txt.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -c 'DNS:web.lab.internal' lab/tls/server-cert.txt
grep -Ec 'TLSv1.2 TLSv1.3' lab/tls/nginx.txt
grep -Ec 'Verify return code: 0 [(]ok[)]' lab/tls/verify.txt
grep -Eic 'alert protocol version' lab/tls/old-protocol.txt
grep -Eo '[0-9]+' lab/tls/expiry.txt | head -1
The certificate names the host in its SAN, nginx allows only TLS 1.2 and 1.3, the client verified the chain with return code 0, the server itself refused TLS 1.1 with a protocol version alert, and the expiry script reports about 396 days. A certificate without the SAN fails in modern browsers even when the common name matches, which is one of the commonest certificate faults on internal servers.
Notes
A real internal CA keeps its root key offline and issues from an intermediate, so that the root can revoke a compromised intermediate. The expiry script is the seed of the monitoring check that stops certificates expiring unnoticed.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.