You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

搭建本地HTTPS服务器时SSL/TLS证书与CSR通用名称字段问题

本地HTTPS服务器证书错误解决指南

你的问题核心不是Common Name(CN)字段设置错了——你把CN设为goose.local是完全正确的。真正的问题是:你最终用在服务器上的是自签名证书,而不是用自己生成的CA证书签发的服务器证书,同时现代浏览器要求证书必须包含Subject Alternative Name(SAN)字段,缺少这个也会触发NET::ERR_CERT_COMMON_NAME_INVALID错误。

从你提供的openssl s_client输出能明确看出来:

Certificate chain
 0 s:/CN=goose.local
   i:/CN=goose.local

这里issuer(i字段)和subject(s字段)都是goose.local,说明证书是自己签自己的,没有经过你生成的CA签发,所以即使你安装了CA证书,浏览器也无法通过信任链验证这个服务器证书。

正确的证书生成与签发流程

1. 重新生成CA证书(可选,若之前的CA没问题可跳过)

openssl req -new -x509 -days 365 -key ca.key -out ca.cert.pem
# 这里CN可以填任意标识,比如「My Local Test CA」,不需要和域名一致
# 其他字段直接回车留空即可

2. 生成服务器密钥和CSR(你之前的操作是对的,确保CN填goose.local)

openssl req -new -sha256 -key goose.local.key -out goose.local.csr
# 这里必须把Common Name设为`goose.local`,其他字段留空即可

3. 创建证书配置文件,添加SAN字段

新建一个server.conf文件,内容如下:

[req]
req_extensions = v3_req
distinguished_name = req_distinguished_name

[req_distinguished_name]

[v3_req]
basicConstraints = CA:FALSE
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
subjectAltName = @alt_names

[alt_names]
DNS.1 = goose.local

这个配置的作用是给服务器证书添加SAN字段,指定域名goose.local,这是现代浏览器强制要求的验证项。

4. 用CA证书签发服务器CSR

执行以下命令生成合法的服务器证书:

openssl x509 -req -in goose.local.csr -CA ca.cert.pem -CAkey ca.key -CAcreateserial -out goose.local.cert.pem -days 365 -sha256 -extfile server.conf -extensions v3_req

5. 配置Go HTTPS服务器

在你的Go代码中,使用刚生成的goose.local.cert.pem和goose.local.key启动服务器,替换之前的自签名证书。

验证修复效果

重新启动服务器后,用openssl s_client测试,应该能看到证书链变成两层:

Certificate chain
 0 s:/CN=goose.local
   i:/CN=My Local Test CA  # 这里是你CA证书的CN,不是goose.local

此时再访问https://goose.local,浏览器就不会再提示证书错误了。

内容的提问来源于stack exchange,提问作者sSunFlowers

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 00:50:44