如何用Python Cryptography区分TLS1.3的两种RSA-PSS证书
如何用cryptography区分RSA Encryption和RSASSA-PSS公钥的证书
问题核心:cryptography会将两种RSA类公钥统一封装为
RSAPublicKey对象,无法直接通过公钥对象的属性区分,但证书的Subject Public Key Info字段中记录的公钥算法OID存在差异:- RSA Encryption(对应你生成的
ca-rsae.cert.pem)的OID:1.2.840.113549.1.1.1 - RSASSA-PSS(对应你生成的
ca-rsa-pss.cert.pem)的OID:1.2.840.113549.1.1.10
- RSA Encryption(对应你生成的
解决思路:直接解析证书的ASN.1结构,提取
Subject Public Key Info中的算法标识符OID,以此区分两种证书。
代码示例
from cryptography import x509 # 读取PEM格式证书并返回公钥算法OID def get_pubkey_algorithm_oid(cert_file_path): with open(cert_file_path, "rb") as f: cert = x509.load_pem_x509_certificate(f.read()) # 提取Subject Public Key Info的算法OID return cert.subject_public_key_info.algorithm_oid # 测试两种证书 rsae_oid = get_pubkey_algorithm_oid("ca-rsae.cert.pem") rsa_pss_oid = get_pubkey_algorithm_oid("ca-rsa-pss.cert.pem") # 输出并判断类型 print(f"ca-rsae证书公钥OID: {rsae_oid}") print(f"ca-rsa-pss证书公钥OID: {rsa_pss_oid}") if rsae_oid == x509.ObjectIdentifier("1.2.840.113549.1.1.1"): print("ca-rsae.cert.pem 使用的是RSA Encryption公钥") elif rsae_oid == x509.ObjectIdentifier("1.2.840.113549.1.1.10"): print("ca-rsae.cert.pem 使用的是RSASSA-PSS公钥") if rsa_pss_oid == x509.ObjectIdentifier("1.2.840.113549.1.1.1"): print("ca-rsa-pss.cert.pem 使用的是RSA Encryption公钥") elif rsa_pss_oid == x509.ObjectIdentifier("1.2.840.113549.1.1.10"): print("ca-rsa-pss.cert.pem 使用的是RSASSA-PSS公钥")
说明
cert.subject_public_key_info.algorithm_oid直接对应OpenSSL命令行输出中Public Key Algorithm字段的内容,是区分两种公钥类型的可靠依据- 可以直接将返回的OID对象与字符串形式的OID或cryptography预定义的OID常量做相等比较
内容的提问来源于stack exchange,提问作者Julien Castiaux
相关产品推荐
相关产品推荐

