1#!/bin/bash -x 2 3 4gmssl sm2keygen -pass 1234 -out rootcakey.pem 5gmssl certgen -C CN -ST Beijing -L Haidian -O PKU -OU CS -CN ROOTCA -days 3650 -key rootcakey.pem -pass 1234 -out rootcacert.pem -key_usage keyCertSign -key_usage cRLSign 6gmssl certparse -in rootcacert.pem 7 8gmssl sm2keygen -pass 1234 -out cakey.pem 9gmssl reqgen -C CN -ST Beijing -L Haidian -O PKU -OU CS -CN "Sub CA" -days 3650 -key cakey.pem -pass 1234 -out careq.pem 10gmssl reqsign -in careq.pem -days 365 -key_usage keyCertSign -path_len_constraint 0 -cacert rootcacert.pem -key rootcakey.pem -pass 1234 -out cacert.pem 11gmssl certparse -in cacert.pem 12 13gmssl sm2keygen -pass 1234 -out signkey.pem 14gmssl reqgen -C CN -ST Beijing -L Haidian -O PKU -OU CS -CN localhost -days 365 -key signkey.pem -pass 1234 -out signreq.pem 15gmssl reqsign -in signreq.pem -days 365 -key_usage digitalSignature -cacert cacert.pem -key cakey.pem -pass 1234 -out signcert.pem 16gmssl certparse -in signcert.pem 17 18gmssl sm2keygen -pass 1234 -out enckey.pem 19gmssl reqgen -C CN -ST Beijing -L Haidian -O PKU -OU CS -CN localhost -days 365 -key enckey.pem -pass 1234 -out encreq.pem 20gmssl reqsign -in encreq.pem -days 365 -key_usage keyEncipherment -cacert cacert.pem -key cakey.pem -pass 1234 -out enccert.pem 21gmssl certparse -in enccert.pem 22 23cat signcert.pem > double_certs.pem 24cat enccert.pem >> double_certs.pem 25cat cacert.pem >> double_certs.pem 26 27sudo gmssl tlcp_server -port 443 -cert double_certs.pem -key signkey.pem -pass 1234 -ex_key enckey.pem -ex_pass 1234 -cacert cacert.pem 1>/dev/null 2>/dev/null & 28sleep 3 29 30gmssl sm2keygen -pass 1234 -out clientkey.pem 31gmssl reqgen -C CN -ST Beijing -L Haidian -O PKU -OU CS -CN Client -days 365 -key clientkey.pem -pass 1234 -out clientreq.pem 32gmssl reqsign -in clientreq.pem -days 365 -key_usage digitalSignature -cacert cacert.pem -key cakey.pem -pass 1234 -out clientcert.pem 33gmssl certparse -in clientcert.pem 34 35# build and install BabaSSL 8.3.1 36openssl version 37openssl s_client -enable_ntls -ntls -connect localhost:443 -no_ticket -CAfile rootcacert.pem 38 39 40