You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

证书未加入tls-ca-bundle.pem的问题排查求助

证书导入问题求助

我不是证书领域专家,查了各类网络资料都没解决问题,来这儿求助。我想把证书xx_exp_2023_11_30.cer加入/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem,操作系统详情见配图。

已执行操作

  • 将证书复制到/etc/pki/ca-trust/source/anchors/目录
  • 执行以下命令,均无报错:
    update-ca-trust force-enable 
    update-ca-trust extract
    
  • 按相关指引执行检查命令:
    openssl x509 -noout -text -in xx_exp_2023_11_30.cer | grep --after-context=2 "X509v3 Basic Constraints" | grep "CA:TRUE"
    

当前问题

/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem中未出现该证书内容,用cat tls-ca-bundle.pem | grep <证书开头字符>无结果,但其他导入的证书可被检索到。已确认证书存放目录正确。

更新信息

更新1

证书被加入/etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt,但未出现在tls-ca-bundle.pem中。我的应用因证书链错误连接失败,推测应用读取的是tls-ca-bundle.pem,请问为何证书仅出现在前者?两者有何区别?

更新2

了解到openssl子目录中的证书为BEGIN TRUSTED CERTIFICATE格式,但我的证书是BEGIN CERTIFICATE格式,不解为何会被归入该目录。

更新3

以下是openssl x509 -noout -text -in xx_exp_2023_11_30.cer的匿名输出内容:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            ser num
        Signature Algorithm: encrytpion
        Issuer: O = XX, CN = TST-XX
        Validity
            Not Before: Nov 30 05:46:42 2021 GMT
            Not After : Nov 30 05:46:42 2023 GMT
        Subject: CN = xx.tst2.dom
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    something
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage:
                Digital Signature, Key Encipherment
            something:
                0-.%+blabla
            X509v3 Subject Key Identifier:
                Something
            X509v3 Authority Key Identifier:
                keyid:Something

            X509v3 CRL Distribution Points:

                Full Name:
                  URI:http://address.crl

            Authority Information Access:
                CA Issuers - URI:http://address.crt

            X509v3 Extended Key Usage:
                TLS Web Server Authentication
            xxxxx:
                0.0
..+.......
            X509v3 Subject Alternative Name:
                DNS:dnslist
    Signature Algorithm: sha256WithRSAEncryption
         ......

内容的提问来源于stack exchange,提问作者Saugat Mukherjee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 13:07:39