You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Python Cryptography证书生成器添加废弃的nsCertType扩展

无OpenSSL依赖添加废弃的nsCertType扩展到Python证书

我明白你想在不依赖OpenSSL的前提下,给证书添加已经废弃的nsCertType扩展——这个需求确实有点棘手,因为主流的Python密码学库比如cryptography默认不会封装这类过时扩展,但其实我们可以通过自定义X509扩展的方式来实现,完全不需要调用外部OpenSSL命令。

关键背景:nsCertType的格式

nsCertType的OID是1.2.840.113549.1.9.7,它的值是一个ASN.1 BIT STRING,每个位对应不同的证书用途:

  • Bit 0: SSL服务器证书
  • Bit 1: SSL客户端证书
  • Bit 2: 邮件签名证书
  • Bit 3: 代码签名证书
  • Bit 4: CA证书(用于签发其他证书)
  • Bit 5: 时间戳证书

纯Python实现方案

我们可以用cryptography的UnrecognizedExtension类来手动添加这个扩展,同时用库自带的ASN.1工具构造符合要求的BIT STRING值。以下是修改后的完整代码:

from cryptography import x509
from cryptography.x509.oid import ExtendedKeyUsageOID
from cryptography.hazmat.primitives import hashes, asn1
from cryptography.hazmat.backends import default_backend
import datetime

# 假设你已经定义了这些变量:subject, inter_ca_cert, inter_server_key, duration_rootca, authority_key_identifier

# 构造nsCertType的BIT STRING值:这里示例设置SSL服务器(bit0)和SSL客户端(bit1)
ns_cert_type_builder = asn1.DERBitStringBuilder()
ns_cert_type_builder.set_bit(0)  # 启用SSL服务器类型
ns_cert_type_builder.set_bit(1)  # 启用SSL客户端类型
# 如果需要其他类型,取消对应注释
# ns_cert_type_builder.set_bit(2)  # 邮件签名
# ns_cert_type_builder.set_bit(4)  # CA证书
ns_cert_type_value = ns_cert_type_builder.build()

# 构建证书并添加所有扩展(包括自定义的nsCertType)
inter_server_cert = x509.CertificateBuilder()\
    .subject_name(subject)\
    .issuer_name(inter_ca_cert.issuer)\
    .public_key(inter_server_key.public_key())\
    .serial_number(x509.random_serial_number())\
    .not_valid_before(datetime.datetime.utcnow())\
    .not_valid_after(datetime.datetime.utcnow() + datetime.timedelta(days=duration_rootca))\
    .add_extension(
        x509.BasicConstraints(ca=False, path_length=0),
        critical=True
    )\
    .add_extension(
        x509.SubjectKeyIdentifier.from_public_key(inter_server_key.public_key()),
        critical=False
    )\
    .add_extension(
        x509.AuthorityKeyIdentifier.from_issuer_subject_key_identifier(authority_key_identifier.value),
        critical=False
    )\
    .add_extension(
        x509.KeyUsage(
            key_cert_sign=False, crl_sign=False, digital_signature=True,
            content_commitment=False, key_encipherment=True, data_encipherment=False,
            key_agreement=True, encipher_only=False, decipher_only=False
        ),
        critical=False
    )\
    .add_extension(
        x509.ExtendedKeyUsage([ExtendedKeyUsageOID.SERVER_AUTH]),
        critical=False
    )\
    # 添加自定义的nsCertType扩展
    .add_extension(
        x509.UnrecognizedExtension(
            oid=x509.ObjectIdentifier("1.2.840.113549.1.9.7"),
            value=ns_cert_type_value
        ),
        critical=False  # 根据你的需求设置是否为critical
    )\
    .sign(inter_ca_key, hashes.SHA256(), default_backend())

代码解释

  1. 构造BIT STRING:用DERBitStringBuilder来精确控制每个位的开关,确保生成符合ASN.1规范的字节值,避免手动编码出错。
  2. 添加自定义扩展:通过UnrecognizedExtension传入nsCertType的OID和构造好的BIT STRING值,就可以把这个废弃扩展加入证书中。
  3. 无外部依赖:整个过程只用到cryptography库自带的模块,完全不需要调用系统的OpenSSL命令。

这样生成的证书就会包含nsCertType扩展,满足你的需求啦。

内容的提问来源于stack exchange,提问作者Gasp0de

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 07:42:56