You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何生成Mac及Windows虚拟机全浏览器兼容的安全自签名证书

生成Mac与Windows虚拟机全浏览器兼容的自签名证书

问题背景

你之前按照如下配置生成了localhost和192.168.1.1的自签名证书:

[req]
distinguished_name = req_distinguished_name
x509_extensions = v3_req
prompt = no
[req_distinguished_name]
C = US
ST = VA
L = SomeCity
O = MyCompany
OU = MyDivision
CN = localhost
[v3_req]
keyUsage = critical, digitalSignature, keyAgreement
extendedKeyUsage = serverAuth
subjectAltName = DNS:localhost,IP:192.168.1.1,IP:127.0.0.1

执行命令:

openssl req -newkey rsa:2048 -x509 -nodes -keyout key.pem -new -out cert.pem -config req.cnf -sha256 -days 3650

并在Mac钥匙串和Windows证书管理器中设置了信任,原本可正常使用,但现在Mac的Chrome 109.0.5414.119、Windows虚拟机的Firefox 109.0.1518.70、Mac的Firefox 109.0均显示“Not Secure”警告,仅Windows虚拟机的Edge和Chrome正常,需要调整生成方式让所有浏览器都认可。

问题原因

  1. 旧配置缺少subjectKeyIdentifier和authorityKeyIdentifier字段,新版本浏览器(尤其是Firefox)对证书合规性要求更严格,缺失这些字段会被判定为无效。
  2. Firefox不依赖系统证书存储,即使在系统层面信任了证书,也需要单独在浏览器内导入并配置信任。
  3. 部分浏览器对keyUsage的组合校验更严格,旧配置的字段覆盖范围不足。

修正后的证书配置

更新req.cnf文件,补充必要的合规字段:

[req]
distinguished_name = req_distinguished_name
x509_extensions = v3_req
prompt = no
[req_distinguished_name]
C = US
ST = VA
L = SomeCity
O = MyCompany
OU = MyDivision
CN = localhost
[v3_req]
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid,issuer
keyUsage = critical, digitalSignature, keyEncipherment, keyAgreement
extendedKeyUsage = serverAuth, clientAuth
subjectAltName = DNS:localhost, IP:192.168.1.1, IP:127.0.0.1
basicConstraints = CA:TRUE
  • subjectKeyIdentifier/authorityKeyIdentifier:补充X.509标准要求的标识字段,避免浏览器合规校验失败。
  • 调整keyUsage:新增keyEncipherment覆盖更多加密场景,保留critical确保浏览器强制校验。
  • basicConstraints = CA:TRUE:标记证书为根CA证书,提升信任等级(自签名证书本身就是根CA)。
  • 扩展extendedKeyUsage:新增clientAuth,兼容客户端认证场景,避免部分浏览器限制。

重新生成证书

备份旧的key.pem和cert.pem后,执行原命令重新生成证书:

openssl req -newkey rsa:2048 -x509 -nodes -keyout key.pem -new -out cert.pem -config req.cnf -sha256 -days 3650

全平台信任配置

Mac系统(Chrome/Firefox)

  1. 系统钥匙串信任:
    • 双击cert.pem,选择添加到系统钥匙串(而非登录钥匙串)。
    • 在Keychain Access的“系统”钥匙串找到该证书,右键选择“显示简介”。
    • 展开“信任”选项,将“使用此证书时”设置为“始终信任”,关闭窗口并输入系统密码确认。
  2. Firefox单独信任:
    • 打开Firefox,输入about:preferences#privacy进入隐私安全设置。
    • 下滑到“证书”区域,点击“查看证书”→“证书颁发机构”→“导入”。
    • 选择cert.pem,勾选“信任由此证书颁发的网站”,点击确定。

Windows虚拟机(Edge/Chrome/Firefox)

  1. 系统证书信任:
    • 右键cert.pem,选择“安装证书”,选择“本地计算机”(而非当前用户),点击下一步。
    • 选择“将所有证书放入下列存储”,点击“浏览”,选择“受信任的根证书颁发机构”,完成导入。
  2. Firefox单独信任:
    • 同Mac端Firefox操作步骤,导入cert.pem并勾选信任网站选项。

验证

分别在以下环境访问https://localhost和https://192.168.1.1:

  • Mac的Chrome、Firefox
  • Windows虚拟机的Edge、Chrome、Firefox
    所有浏览器应显示地址栏安全锁图标,无“Not Secure”警告。

内容的提问来源于stack exchange,提问作者SoftTimur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 00:01:20