我需要文件的哈希名稱以將其發布到Stunnel的CApath目錄中。我在此目錄中有一些證書,它們運行良好。另外,我有一個服務器sert和服務器密鑰:cert = c:\Program Files (x86)\stunnel\server_cert.pem key = c:\Program> Files (x86)\stunnel\private\server_key.pem當我嘗試計算新證書的哈希值時,出現錯誤:/etc/pki/tls/misc/c_hash cert.pemunable to load certificate 140603809879880:error:0906D06C:PEMroutines:PEM_read_bio:no start line:pem_lib.c:703:Expecting: TRUSTED CERTIFICATE據我了解,我必須簽署證書,但我不知道該怎么做。請提供解決方案。PS:訊息unable to load certificate 140603809879880:error:0906D06C:PEMroutines:PEM_read_bio:no start line:pem_lib.c:703:Expecting: TRUSTED CERTIFICATE:我為cert.pem制作c_hash時發布的信息這不是server_cert.pem,這是Root_CA,內容類似-----BEGIN CERTIFICATE----- ...6UXBNSDVg5rSx60=.. -----END CERTIFICATE-----當我寫openssl x509 -noout -text -in cert.pem在控制臺面板中,我看到以下信息: Certificate: Data: Version: 3 (0x2) Serial Number: 1 (0x1) Signature Algorithm: sha1WithRSAEncryption Issuer: C=BE, ST=BB, L=BB, O=BANKSYS NV, OU=SCY, CN=TEST Root CA Validity Not Before: May 31 08:06:40 2005 GMT Not After : May 31 08:06:40 2020 GMT Subject: C=BE, ST=BB, L=BB, O=BB NV, OU=SCY, CN=TEST Root CA Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:82:c8:58:1e:e5:7a:b2:63:a6:15:bd:f9:bb:1f:............ Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:TRUE X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Subject Key Identifier: 76:70:AB:92:9B:B1:26:CE:9E:93:D8:77:4F:78:0D:B8:D4:6C:DA:C6 Signature Algorithm: sha1WithRSAEncryption 2c:7e:bd:3f:da:48:a4:df:8d:7c:96:58:f7:87:bd:e7:16:24:...............
3 回答

九州編程
TA貢獻1785條經驗 獲得超4個贊
我的情況有些不同。解決方案是從證書和私鑰部分之外的所有內容中剝離.pem并反轉它們出現的順序。從pfx轉換為pem文件后,證書如下所示:
Bag Attributes
localKeyID: ...
issuer=...
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
Bag Attributes
more garbage...
-----BEGIN PRIVATE KEY-----
...
-----END PRIVATE KEY-----
更正文件后,它只是:
-----BEGIN PRIVATE KEY-----
...
-----END PRIVATE KEY-----
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
添加回答
舉報
0/150
提交
取消