求助:在.NET Framework 4.8中从CER和KEY文件创建PEM证书的方案
.NET Framework 4.8 从CER和KEY文件创建X509Certificate2的解决方案
由于.NET Framework 4.8原生不支持X509Certificate2.CreateFromPemFile方法,这里通过BouncyCastle库实现等效功能,解决你遇到的异常问题:
第一步:安装BouncyCastle依赖
在项目中安装兼容.NET Framework 4.8的BouncyCastle NuGet包,推荐使用Portable.BouncyCastle(选择最新稳定版本即可)。
第二步:实现转换代码
以下代码可正确读取PKCS#8格式私钥(你的KEY文件开头为-----BEGIN PRIVATE KEY-----,属于PKCS#8)和PEM格式证书,合并为X509Certificate2对象:
using System; using System.IO; using System.Security.Cryptography.X509Certificates; using Org.BouncyCastle.Crypto; using Org.BouncyCastle.OpenSsl; using Org.BouncyCastle.X509; using Org.BouncyCastle.Security; public static class CertificateHelper { public static X509Certificate2 CreateCertificate(string certificatePath, string keyPath) { // 读取证书和私钥文件内容 string certPem = File.ReadAllText(certificatePath); string keyPem = File.ReadAllText(keyPath); // 解析PEM格式证书 X509CertificateParser certParser = new X509CertificateParser(); X509Certificate bcCert = certParser.ReadCertificate(PemHelper.ExtractPemBytes(certPem)); // 解析PKCS#8格式私钥 AsymmetricCipherKeyPair bcKeyPair; using (StringReader keyReader = new StringReader(keyPem)) { PemReader pemReader = new PemReader(keyReader); bcKeyPair = (AsymmetricCipherKeyPair)pemReader.ReadObject(); } // 将BouncyCastle对象转换为.NET原生X509Certificate2 X509Certificate2 cert = new X509Certificate2(bcCert.GetEncoded()); AsymmetricSecurityKey securityKey = DotNetUtilities.ToAsymmetricSecurityKey(bcKeyPair.Private); RSACryptoServiceProvider rsa = (RSACryptoServiceProvider)securityKey.GetAsymmetricAlgorithm(typeof(RSACryptoServiceProvider), false); cert.PrivateKey = rsa; // 若需导出为PFX格式,可取消下方注释并设置密码 // return new X509Certificate2(cert.Export(X509ContentType.Pfx, "your-password"), "your-password"); return cert; } } // 辅助类:提取PEM内容中的Base64字节数组 internal static class PemHelper { public static byte[] ExtractPemBytes(string pemContent) { string[] lines = pemContent.Split(new[] { "\r\n", "\n" }, StringSplitOptions.RemoveEmptyEntries); int startLine = Array.FindIndex(lines, line => line.StartsWith("-----BEGIN")); int endLine = Array.FindIndex(lines, line => line.StartsWith("-----END")); if (startLine == -1 || endLine == -1 || endLine <= startLine) throw new InvalidDataException("无效的PEM格式内容"); string base64Content = string.Join("", lines[startLine + 1..endLine]); return Convert.FromBase64String(base64Content); } }
关键说明
- 私钥格式适配:你的KEY文件是PKCS#8标准格式,BouncyCastle的
PemReader可直接解析,无需额外格式转换。 - 跨库对象转换:通过
DotNetUtilities工具类将BouncyCastle的证书、私钥对象转换为.NET原生类型,保证在.NET Framework 4.8中的兼容性。 - 异常规避:若之前使用BouncyCastle出现异常,大概率是私钥解析逻辑错误或版本不兼容,上述代码已针对这类问题做了适配。
内容的提问来源于stack exchange,提问作者Martin Mulder
相关产品推荐
相关产品推荐

