You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用C语言与OpenSSL解析X509自签名证书密钥时,无法通过->访问结构体成员的问题求助

解决OpenSSL解析X509证书密钥时的结构体访问问题

Hey there! The issue you're facing is almost certainly tied to OpenSSL version differences—the 2013 article you referenced uses older OpenSSL APIs that aren't compatible with modern versions (1.1.0 and later). Let's break down how to fix this, plus alternative ways to extract key details.

Why you can't use the -> operator

Before OpenSSL 1.1.0, many core structs like X509, EVP_PKEY, and RSA let you directly access their internal members via ->. But starting with 1.1.0, these structs were made opaque to improve API stability and security. Directly accessing their fields is no longer allowed—you have to use the official getter/setter functions provided by OpenSSL.

Fixing your code with modern OpenSSL APIs

First, make sure you're including all necessary headers:

#include <openssl/x509.h>
#include <openssl/evp.h>
#include <openssl/rsa.h>
#include <openssl/bn.h>
#include <openssl/err.h>

Then replace your old code snippets with these modern equivalents:

1. Get the public key algorithm NID

Instead of directly digging into cert->cert_info->key->algor->algorithm, use:

// Get the public key from the certificate
EVP_PKEY *pkey = X509_get_pubkey(cert);
if (!pkey) {
    // Handle error—use ERR_print_errors_fp(stderr) to debug
    return -1;
}

// Get the algorithm ID
int pubkey_algonid = EVP_PKEY_id(pkey);

2. Extract RSA public key components (e and n)

Instead of accessing pkey->pkey.rsa directly, use the RSA getter functions:

// Extract RSA key from EVP_PKEY
RSA *rsa_key = EVP_PKEY_get1_RSA(pkey);
if (!rsa_key) {
    EVP_PKEY_free(pkey);
    // Handle error
    return -1;
}

// Get the exponent (e) and modulus (n) using OpenSSL's getter functions
const BIGNUM *rsa_e = rsa_get0_e(rsa_key);
const BIGNUM *rsa_n = rsa_get0_n(rsa_key);

// Convert to human-readable strings
char *rsa_e_dec = BN_bn2dec(rsa_e);
char *rsa_n_hex = BN_bn2hex(rsa_n);

// Use the strings... don't forget to free them later!
printf("Exponent (decimal): %s\n", rsa_e_dec);
printf("Modulus (hex): %s\n", rsa_n_hex);

// Cleanup
BN_free(rsa_e_dec);
BN_free(rsa_n_hex);
RSA_free(rsa_key);
EVP_PKEY_free(pkey);

When compiling, make sure to link against the OpenSSL crypto library:

gcc your_code.c -o your_code -lcrypto

Alternative ways to get certificate key details

If you don't need to do this programmatically, the OpenSSL command line tool is a quick option:

  1. Extract the public key from your certificate:
    openssl x509 -in your_cert.pem -pubkey -noout > pubkey.pem
    
  2. Print the key's details (including exponent and modulus):
    openssl rsa -pubin -in pubkey.pem -text -noout
    

This will output the RSA components in both hex and decimal formats, no code required.

内容的提问来源于stack exchange,提问作者lanpesk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 13:52:47