如何从现有叶证书生成中间证书和根证书? [英] How to generate intermediate and root cert from an existing leaf certificate?

查看:47
本文介绍了如何从现有叶证书生成中间证书和根证书?的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

现在我有一个 X509 叶证书.从认证路径来看,里面有一个中间证书和一个根证书.

Now i have a X509 leaf certificate. From the certification path to see, there's a intermediate cert and a root cert in it.

我想生成中间证书(..CA-G3) 和根证书(VerSign).目前,我的方法是双击中间的,然后单击复制到文件.."将其导出.对 root 也做同样的事情.这种方式可以纠正生成中间/根证书吗?

I want to generate the intermediate cert(..CA- G3) and the root cert(VerSign). Currently, my way is to double click the intermediate one and then click "Copy to file.." to export it. Do same for the root one too. Is this way to correct to generate intermediate/root certs?

从我的测试结果来看,生成的根证书似乎带有错误的指纹.指纹与服务器端的不匹配.

From my test result, it seems the generated root cert with wrong fingerprint. The fingerpring doesn't match the one on server side.

任何人都可以帮助如何正确生成中间/根证书?

Anyone can help on how to generate intermediate/root certs correctly?

推荐答案

[提供答案...,也许这是获取 SSL 服务器使用的所有证书的替代方法]

[supply the answer... , maybe this is an alternative approach to get all certs that the SSL server using]

通过 OpenSSL 命令检索中间和根证书:

To retrieve the ntermediate and root certs by OpenSSL command:

  openssl s_client -showcerts -connect [host]:[port]

这篇关于如何从现有叶证书生成中间证书和根证书?的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆