Before creating the SSL key set required by the Web server, you must generate a Certificate Authority (CA) SSL key pair. A CA SSL public certificate is distributed to client systems of the Satellite or Proxy. The RHN SSL Maintenance Tool allows you to generate a CA SSL key pair if needed and re-use it for all subsequent RHN server deployments.
The build process automatically creates the key pair and public RPM for distribution to clients. All CA components end up in the build directory specified at the command line, typically /root/ssl-build
(or /etc/sysconfig/rhn/ssl
for older Satellites and Proxies). To generate a CA SSL key pair, issue a command like this:
Replace the example values with those appropriate for your organization. This will result in the following relevant files in the specified build directory: