Step 3: generating certificates and keys

  • Now we can start generating the certificates and keys. Begin with the certificate authority (CA) - the root certificate file that will be used to sign other certificates and keys:
      ./easyrsa build-ca nopass
  • Common name must be the domain of your server. For example, when using flespi platform, it is ‘*.flespi.gw’. When prompted the sign and commit the certificate, type y and press "Enter". '*.flespi.gw' – where * is flespi platform assigned 5 digit number.
  • Next, build the server certificate and key:
      ./easyrsa --subject-alt-name="DNS:*.flespi.gw" build-server-full platform nopass