From: Eleanor McHugh Date: 2009-11-27T20:52:16+09:00 Subject: Re: creating certificates and public and private keys On 27 Nov 2009, at 11:01, Dave English wrote: > In message , Adam Akhtar writes >> Hi im going to have to create a lot of public and private keys for >> clients and would like to automate the process by using a script (in >> ruby of course). >> >> This is for an openvpn setup and currently ive been MANUALY creating >> keys with the easy-rsa bat file that comes with it but id like to >> automate it. >> >> Is there a ruby libary available that would allow me to create public >> and private keys if i already have a CA. Would openvpn recognize these >> keys (are keys, keys no matter what language they are created in??? im >> not hot on cryptology) >> >> The other option would be to just execute the bat file from my ruby >> script and simulate the keyboard to respond to the various prompts. I >> havent doent this before so im not sure if this is easier or harder than >> above. Any tips or pointers will really help! > > I haven't done this myself. > > But the common Swiss army knife for this is OpenSSL. > > Ruby provides Ruby::OpenSSL. Apparently that library isn't the easiest to use, but http://rubyforge.org/projects/sslplaypen/ has examples which may help. > > The alternative is to use drive the openssl command line, that may be easier as there are plenty of examples for generating keys using OpenSSL. The nascent http://rubyforge.org/projects/simplessl/ used the openssl command line & might be a good starting point. > > Other here may well know better, of course Ruby::OpenSSL is not the friendliest of libraries due to a lack of detailed documentation but you can find some coverage by Romek (the author of SSL PlayPen) and myself in the "Semantic DNS" presentation available at the link in my signature. That's mostly to do with ad hoc key generation in a hybrid crypto system but there may be something there that could be useful for a CA scenario. Ellie Eleanor McHugh Games With Brains http://slides.games-with-brains.net ---- raise ArgumentError unless @reality.responds_to? :reason