You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core生成Ed25519自签X.509证书参数ANY NULL合规问题求助

解决Ed25519自签证书AlgorithmIdentifier带NULL参数的问题

问题出在你使用了通用的Asn1SignatureFactory生成Ed25519签名,这个工厂类默认会为Ed25519的AlgorithmIdentifier添加NULL参数,不符合RFC8410的规范要求。

解决步骤

替换通用签名工厂为BouncyCastle提供的Ed25519专属签名工厂:Ed25519SignatureFactory。这个类是为Ed25519算法量身实现的,会自动遵循RFC8410要求,省略AlgorithmIdentifier中的parameters字段。

修改后的核心代码

private X509Certificate CreateSelfSignedCertificate(X509Name subjectName, Pkcs10CertificationRequest csr, Ed25519PrivateKeyParameters privateKey, DateTime notBefore, DateTime notAfter)
{
    var certGen = new X509V3CertificateGenerator();

    var serialNumber = new BigInteger("2651512");
    certGen.SetSerialNumber(serialNumber);

    certGen.SetIssuerDN(subjectName);
    certGen.SetSubjectDN(subjectName);
    certGen.SetNotBefore(notBefore);
    certGen.SetNotAfter(notAfter);
    certGen.SetPublicKey(csr.GetPublicKey());

    certGen.AddExtension(X509Extensions.SubjectKeyIdentifier, false, new SubjectKeyIdentifierStructure(csr.GetPublicKey()));
    var authorityKeyIdentifier = new AuthorityKeyIdentifierStructure(csr.GetPublicKey());

    certGen.AddExtension(X509Extensions.AuthorityKeyIdentifier, false, authorityKeyIdentifier);
    certGen.AddExtension(X509Extensions.BasicConstraints, false, CreateCustomExtensionValueRoot());

    // 替换为Ed25519专属签名工厂
    var signatureFactory = new Ed25519SignatureFactory(privateKey);

    return certGen.Generate(signatureFactory);
}

验证效果

修改后重新生成证书,用ASN.1解码器分析签名的AlgorithmIdentifier段,会看到parameters字段已被省略,符合RFC8410规范:

signature AlgorithmIdentifier SEQUENCE (1 elem)
algorithm OBJECT IDENTIFIER 1.3.101.112 curveEd25519 (EdDSA 25519 signature algorithm)

内容的提问来源于stack exchange,提问作者Sedat ÇANDIR

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 08:15:00