如何用Python Cryptography识别证书链中的终端实体证书?
识别Authenticode签名中的终端实体证书
要自动识别证书链中的终端实体(代码签名)证书,可基于以下核心特征和逻辑实现:
核心判断依据
- 排除CA证书:CA证书会携带
Basic Constraints扩展,且其中的ca字段为True。终端实体证书要么无此扩展,要么ca字段为False。 - 验证代码签名用途:终端实体证书的
Extended Key Usage扩展中必须包含Code Signing(OID: 1.3.6.1.5.5.7.3.3)标识。 - 确认链末端身份:终端实体证书的Subject不会匹配链中任何其他证书的Issuer(因为它是链的最末端,不负责签发其他证书)。
实现代码
from cryptography.x509 import ExtensionNotFound, ObjectIdentifier CODE_SIGNING_OID = ObjectIdentifier("1.3.6.1.5.5.7.3.3") def find_end_entity_certificate(cert_chain): # 预收集所有证书的Issuer信息,用于后续链关系校验 issuer_set = {cert.issuer for cert in cert_chain} for cert in cert_chain: is_end_entity = True # 检查是否为CA证书 try: basic_constraints = cert.extensions.get_extension_for_class(cert.x509.BasicConstraints) if basic_constraints.value.ca: is_end_entity = False except ExtensionNotFound: # 无Basic Constraints扩展,默认是终端实体证书 pass if not is_end_entity: continue # 验证是否具备代码签名用途 try: eku_ext = cert.extensions.get_extension_for_class(cert.x509.ExtendedKeyUsage) if CODE_SIGNING_OID not in eku_ext.value: is_end_entity = False except ExtensionNotFound: # 部分旧版代码签名证书可能无EKU扩展,此处保留判断 pass if not is_end_entity: continue # 确认该证书不签发其他证书(链末端) if cert.subject in issuer_set: is_end_entity = False if is_end_entity: return cert return None # 使用示例 end_cert = find_end_entity_certificate(certChain) if end_cert: print("终端实体证书信息:") print(f"Subject: {end_cert.subject}") print(f"Issuer: {end_cert.issuer}") else: print("未找到有效终端实体证书")
针对你的示例说明
在你提供的GPU-Z证书链中:
- 前两个是时间戳服务相关证书,其扩展用途为时间戳签名,不符合代码签名要求,会被筛选排除。
- 第三个证书(Subject为
TechPowerUp LLC):无CA标识、具备代码签名用途、且其Subject未出现在其他证书的Issuer中,是目标终端实体证书。 - 第四个是CA签发证书,携带CA标识,会被排除。
内容的提问来源于stack exchange,提问作者synner
相关产品推荐
相关产品推荐

