证书未加入tls-ca-bundle.pem的问题排查求助
证书导入问题求助
我不是证书领域专家,查了各类网络资料都没解决问题,来这儿求助。我想把证书xx_exp_2023_11_30.cer加入/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem,操作系统详情见配图。
已执行操作
- 将证书复制到
/etc/pki/ca-trust/source/anchors/目录 - 执行以下命令,均无报错:
update-ca-trust force-enable update-ca-trust extract - 按相关指引执行检查命令:
openssl x509 -noout -text -in xx_exp_2023_11_30.cer | grep --after-context=2 "X509v3 Basic Constraints" | grep "CA:TRUE"
当前问题
/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem中未出现该证书内容,用cat tls-ca-bundle.pem | grep <证书开头字符>无结果,但其他导入的证书可被检索到。已确认证书存放目录正确。
更新信息
更新1
证书被加入/etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt,但未出现在tls-ca-bundle.pem中。我的应用因证书链错误连接失败,推测应用读取的是tls-ca-bundle.pem,请问为何证书仅出现在前者?两者有何区别?
更新2
了解到openssl子目录中的证书为BEGIN TRUSTED CERTIFICATE格式,但我的证书是BEGIN CERTIFICATE格式,不解为何会被归入该目录。
更新3
以下是openssl x509 -noout -text -in xx_exp_2023_11_30.cer的匿名输出内容:
Certificate: Data: Version: 3 (0x2) Serial Number: ser num Signature Algorithm: encrytpion Issuer: O = XX, CN = TST-XX Validity Not Before: Nov 30 05:46:42 2021 GMT Not After : Nov 30 05:46:42 2023 GMT Subject: CN = xx.tst2.dom Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: something Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Key Usage: Digital Signature, Key Encipherment something: 0-.%+blabla X509v3 Subject Key Identifier: Something X509v3 Authority Key Identifier: keyid:Something X509v3 CRL Distribution Points: Full Name: URI:http://address.crl Authority Information Access: CA Issuers - URI:http://address.crt X509v3 Extended Key Usage: TLS Web Server Authentication xxxxx: 0.0 ..+....... X509v3 Subject Alternative Name: DNS:dnslist Signature Algorithm: sha256WithRSAEncryption ......
内容的提问来源于stack exchange,提问作者Saugat Mukherjee
相关产品推荐
相关产品推荐

