\documentclass[10pt,a4paper]{article} % Packages \usepackage{fancyhdr} % For header and footer \usepackage{multicol} % Allows multicols in tables \usepackage{tabularx} % Intelligent column widths \usepackage{tabulary} % Used in header and footer \usepackage{hhline} % Border under tables \usepackage{graphicx} % For images \usepackage{xcolor} % For hex colours %\usepackage[utf8x]{inputenc} % For unicode character support \usepackage[T1]{fontenc} % Without this we get weird character replacements \usepackage{colortbl} % For coloured tables \usepackage{setspace} % For line height \usepackage{lastpage} % Needed for total page number \usepackage{seqsplit} % Splits long words. %\usepackage{opensans} % Can't make this work so far. Shame. Would be lovely. \usepackage[normalem]{ulem} % For underlining links % Most of the following are not required for the majority % of cheat sheets but are needed for some symbol support. \usepackage{amsmath} % Symbols \usepackage{MnSymbol} % Symbols \usepackage{wasysym} % Symbols %\usepackage[english,german,french,spanish,italian]{babel} % Languages % Document Info \author{mdoehle} \pdfinfo{ /Title (pki-openssl.pdf) /Creator (Cheatography) /Author (mdoehle) /Subject (PKI / openSSL Cheat Sheet) } % Lengths and widths \addtolength{\textwidth}{6cm} \addtolength{\textheight}{-1cm} \addtolength{\hoffset}{-3cm} \addtolength{\voffset}{-2cm} \setlength{\tabcolsep}{0.2cm} % Space between columns \setlength{\headsep}{-12pt} % Reduce space between header and content \setlength{\headheight}{85pt} % If less, LaTeX automatically increases it \renewcommand{\footrulewidth}{0pt} % Remove footer line \renewcommand{\headrulewidth}{0pt} % Remove header line \renewcommand{\seqinsert}{\ifmmode\allowbreak\else\-\fi} % Hyphens in seqsplit % This two commands together give roughly % the right line height in the tables \renewcommand{\arraystretch}{1.3} \onehalfspacing % Commands \newcommand{\SetRowColor}[1]{\noalign{\gdef\RowColorName{#1}}\rowcolor{\RowColorName}} % Shortcut for row colour \newcommand{\mymulticolumn}[3]{\multicolumn{#1}{>{\columncolor{\RowColorName}}#2}{#3}} % For coloured multi-cols \newcolumntype{x}[1]{>{\raggedright}p{#1}} % New column types for ragged-right paragraph columns \newcommand{\tn}{\tabularnewline} % Required as custom column type in use % Font and Colours \definecolor{HeadBackground}{HTML}{333333} \definecolor{FootBackground}{HTML}{666666} \definecolor{TextColor}{HTML}{333333} \definecolor{DarkBackground}{HTML}{2F12A3} \definecolor{LightBackground}{HTML}{F2F0F9} \renewcommand{\familydefault}{\sfdefault} \color{TextColor} % Header and Footer \pagestyle{fancy} \fancyhead{} % Set header to blank \fancyfoot{} % Set footer to blank \fancyhead[L]{ \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{C} \SetRowColor{DarkBackground} \vspace{-7pt} {\parbox{\dimexpr\textwidth-2\fboxsep\relax}{\noindent \hspace*{-6pt}\includegraphics[width=5.8cm]{/web/www.cheatography.com/public/images/cheatography_logo.pdf}} } \end{tabulary} \columnbreak \begin{tabulary}{11cm}{L} \vspace{-2pt}\large{\bf{\textcolor{DarkBackground}{\textrm{PKI / openSSL Cheat Sheet}}}} \\ \normalsize{by \textcolor{DarkBackground}{mdoehle} via \textcolor{DarkBackground}{\uline{cheatography.com/23234/cs/5082/}}} \end{tabulary} \end{multicols}} \fancyfoot[L]{ \footnotesize \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{LL} \SetRowColor{FootBackground} \mymulticolumn{2}{p{5.377cm}}{\bf\textcolor{white}{Cheatographer}} \\ \vspace{-2pt}mdoehle \\ \uline{cheatography.com/mdoehle} \\ \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Cheat Sheet}} \\ \vspace{-2pt}Published 31st August, 2015.\\ Updated 11th May, 2016.\\ Page {\thepage} of \pageref{LastPage}. \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Sponsor}} \\ \SetRowColor{white} \vspace{-5pt} %\includegraphics[width=48px,height=48px]{dave.jpeg} Measure your website readability!\\ www.readability-score.com \end{tabulary} \end{multicols}} \begin{document} \raggedright \raggedcolumns % Set font size to small. Switch to any value % from this page to resize cheat sheet text: % www.emerson.emory.edu/services/latex/latex_169.html \footnotesize % Small font. \begin{multicols*}{2} \begin{tabularx}{8.4cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{8.4cm}}{\bf\textcolor{white}{Certificate Signing Request (CSR)}} \tn \SetRowColor{white} \mymulticolumn{1}{x{8.4cm}}{{\bf{Generate a new private key and Certificate Signing Request}} \newline % Row Count 2 (+ 2) `openssl req -out CSR.csr -new -newkey rsa:2048 -nodes -sha256 -keyout privateKey.key` \newline % Row Count 4 (+ 2) {\bf{Generate a self-signed certificate}} \newline % Row Count 5 (+ 1) `openssl req -x509 -sha256 -nodes -days 365 -newkey rsa:2048 -keyout privateKey.key -out certificate.crt` \newline % Row Count 8 (+ 3) {\bf{Generate a certificate signing request (CSR) for an existing private key}} \newline % Row Count 10 (+ 2) `openssl req -out CSR.csr -key privateKey.key -new` \newline % Row Count 12 (+ 2) {\bf{Generate a certificate signing request based on an existing certificate}} \newline % Row Count 14 (+ 2) `openssl x509 -x509toreq -in certificate.crt -out CSR.csr -signkey privateKey.key` \newline % Row Count 16 (+ 2) {\bf{Remove a passphrase from a private key}} \newline % Row Count 17 (+ 1) `openssl rsa -in privateKey.pem -out newPrivateKey.pem`% Row Count 19 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{8.4cm}}{\bf\textcolor{white}{Check Files}} \tn \SetRowColor{white} \mymulticolumn{1}{x{8.4cm}}{{\bf{Check a Certificate Signing Request (CSR)}} \newline % Row Count 1 (+ 1) `openssl req -text -noout -verify -in CSR.csr` \newline % Row Count 2 (+ 1) {\bf{Check a private key}} \newline % Row Count 3 (+ 1) `openssl rsa -in privateKey.key -check` \newline % Row Count 4 (+ 1) {\bf{Check a certificate}} \newline % Row Count 5 (+ 1) `openssl x509 -in certificate.crt -text -noout` \newline % Row Count 6 (+ 1) {\bf{Check a PKCS\#12 file (.pfx or .p12)}} \newline % Row Count 7 (+ 1) `openssl pkcs12 -info -in keyStore.p12`% Row Count 8 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{8.4cm}}{\bf\textcolor{white}{Debugging}} \tn \SetRowColor{white} \mymulticolumn{1}{x{8.4cm}}{{\bf{Print certificate}} \newline % Row Count 1 (+ 1) `openssl x509 -noout -text -in certificate.crt` \newline % Row Count 2 (+ 1) {\bf{Check an SSL connection. All the certificates (including Intermediates) should be displayed}} \newline % Row Count 4 (+ 2) `openssl s\_client -connect www.paypal.com:443`% Row Count 5 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{8.4cm}}{\bf\textcolor{white}{Remove Passphrase}} \tn \SetRowColor{white} \mymulticolumn{1}{x{8.4cm}}{{\bf{Convert a PKCS\#12 file (.pfx .p12) containing a private key and certificates to PEM}} \newline % Row Count 2 (+ 2) `openssl pkcs12 -in keyStore.p12 -out keyStore.pem -nodes` \newline % Row Count 4 (+ 2) {\bf{Remove Passphrase from key-file}} \newline % Row Count 5 (+ 1) `openssl rsa -in example.key -out example.nocrypt.key`% Row Count 7 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{8.4cm}}{\bf\textcolor{white}{Performance}} \tn \SetRowColor{white} \mymulticolumn{1}{x{8.4cm}}{{\bf{Check the SSL performance}} \newline % Row Count 1 (+ 1) `openssl speed sha1` \newline % Row Count 2 (+ 1) `openssl speed aes-256-cbc` \newline % Row Count 3 (+ 1) `openssl speed -evp aes-256-cbc`% Row Count 4 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{8.4cm}}{\bf\textcolor{white}{How to get a A+ at SSL-Labs}} \tn \SetRowColor{white} \mymulticolumn{1}{x{8.4cm}}{{\bf{Check versions}} \newline % Row Count 1 (+ 1) `\# openssl version` \newline % Row Count 2 (+ 1) `OpenSSL 1.0.1e 11 Feb 2013` \newline % Row Count 3 (+ 1) `\# apache2 -v` \newline % Row Count 4 (+ 1) `Server version: Apache/2.2.22 (Debian)` \newline % Row Count 5 (+ 1) `Server built: Aug 18 2015 09:50:52` \newline % Row Count 6 (+ 1) {\bf{Enable mods}} \newline % Row Count 7 (+ 1) `a2enmod ssl` \newline % Row Count 8 (+ 1) `a2enmod headers` \newline % Row Count 9 (+ 1) `a2enmod setenvif` \newline % Row Count 10 (+ 1) {\bf{Configure virtual host}} \newline % Row Count 11 (+ 1) ` SSLEngine on` \newline % Row Count 12 (+ 1) ` ` \newline % Row Count 13 (+ 1) ` SSLHonorCipherOrder On` \newline % Row Count 14 (+ 1) ` SSLCipherSuite \seqsplit{ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-E`} \newline % Row Count 19 (+ 5) ` SSLProtocol -ALL +TLSv1 +TLSv1.1 +TLSv1.2` \newline % Row Count 20 (+ 1) ` SSLCertificateFile \seqsplit{/etc/ssl/www.example.com.pem`} \newline % Row Count 22 (+ 2) ` SSLCertificateKeyFile \seqsplit{/etc/ssl/www.example.com.key`} \newline % Row Count 24 (+ 2) ` SSLCertificateChainFile /etc/ssl/chain.pem` \newline % Row Count 25 (+ 1) ` ` \newline % Row Count 26 (+ 1) ` SSLStrictSNIVHostCheck On` \newline % Row Count 27 (+ 1) ` ` \newline % Row Count 28 (+ 1) ` Header always set \seqsplit{Strict-Transport-Security} "max-age=63072000; includeSubdomains; preload"` \newline % Row Count 30 (+ 2) } \tn \end{tabularx} \par\addvspace{1.3em} \vfill \columnbreak \begin{tabularx}{8.4cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{8.4cm}}{\bf\textcolor{white}{How to get a A+ at SSL-Labs (cont)}} \tn \SetRowColor{white} \mymulticolumn{1}{x{8.4cm}}{` ` \newline % Row Count 1 (+ 1) ` \textless{}FilesMatch "\textbackslash{}.(cgi|shtml|phtml|php)\$"\textgreater{}` \newline % Row Count 2 (+ 1) ` SSLOptions +StdEnvVars` \newline % Row Count 3 (+ 1) ` \textless{}/FilesMatch\textgreater{}` \newline % Row Count 4 (+ 1) ` \textless{}Directory /usr/lib/cgi-bin\textgreater{}` \newline % Row Count 5 (+ 1) ` SSLOptions +StdEnvVars` \newline % Row Count 6 (+ 1) ` \textless{}/Directory\textgreater{}` \newline % Row Count 7 (+ 1) ` ` \newline % Row Count 8 (+ 1) ` BrowserMatch "MSIE {[}2-6{]}" \textbackslash{} ` \newline % Row Count 9 (+ 1) ` nokeepalive ssl-unclean-shutdown \textbackslash{} ` \newline % Row Count 10 (+ 1) ` downgrade-1.0 force-response-1.0` \newline % Row Count 11 (+ 1) ` \# MSIE 7 and newer should be able to use keepalive` \newline % Row Count 13 (+ 2) ` BrowserMatch "MSIE {[}17-9{]}" ssl-unclean-shutdown`% Row Count 15 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} % That's all folks \end{multicols*} \end{document}