You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PKI.js V2添加CSR主体备用名称(SAN)失败求助

Trouble Adding DNS Subject Alternative Name (SAN) to CSR in PKI.js V2 (Works in V1)

I have a fully functional implementation based on PKI.js V1 and the WebCrypto API that successfully adds DNS-type Subject Alternative Names (SAN) to Certificate Signing Requests (CSRs) without any issues. However, when trying to replicate this functionality in PKI.js V2, the code fails to work as expected, and I'm struggling to pinpoint the root cause.

Background on Working V1 Setup

  • I used the CSRhelp sample project (which doesn't include SAN support by default)
  • After replacing the code at line 516 in csrhelp-master\app\src\csrhelps\CsrhelpService.js, the SAN addition worked perfectly.

Broken V2 Setup

  • I'm using the PKCS#10 complex sample project for V2
  • After modifying the code at line 16784 in PKCS10_complex_example.js, the functionality breaks entirely.

Key Troubleshooting Areas to Check

Since PKI.js V2 introduced significant API refactoring compared to V1, here are the most likely issues and fixes to investigate:

  1. Adapt to V2's API Structure
    PKI.js V2 overhauled how extensions like SAN are constructed and attached to CSRs. The V1 approach won't directly translate. Ensure your code follows V2's pattern for building SAN extensions:

    // Create SAN extension with DNS entries
    const san = new pkijs.SubjectAlternativeName();
    san.names = [
        new pkijs.GeneralName({ type: 2, value: "your-domain.com" }),
        new pkijs.GeneralName({ type: 2, value: "www.your-domain.com" })
    ];
    
    // Wrap SAN as a CSR extension
    const sanExtension = new pkijs.Extension({
        extnID: "2.5.29.17", // OID for Subject Alternative Name
        critical: false,
        extnValue: san.toSchema().toBER(false)
    });
    
    // Add extension request to CSR attributes
    if (!csr.attributes) csr.attributes = [];
    csr.attributes.push(new pkijs.Attribute({
        type: "1.2.840.113549.1.9.14", // Extension Request OID
        values: [new pkijs.Extensions({ extensions: [sanExtension] })]
    }));
    

    Verify that your modified code aligns with this structure, rather than reusing V1's old method calls.

  2. Confirm You're Modifying the Correct Code Line
    Line numbers in minified/concatenated files like PKCS10_complex_example.js can vary depending on the exact version of the sample. Double-check that line 16784 is indeed the section where CSR extensions are being constructed or added—if not, you might be modifying unrelated code.

  3. Check for Console Errors
    Open your browser's developer tools and check the console for any uncaught exceptions or warning messages. PKI.js V2 provides more detailed error logging for issues like invalid extension encoding, incorrect OIDs, or missing required fields, which can quickly point you to the problem.

  4. Validate WebCrypto Interoperability
    While the WebCrypto API itself is largely consistent, PKI.js V2 has stricter requirements for key formats and algorithm parameters. Ensure your key generation and signing workflow is compatible with V2's expectations (e.g., correct key usages, proper algorithm identifiers).

If you can share the exact code snippet you're replacing in the V2 sample, along with any console error messages, it'll be much easier to diagnose the issue precisely.

内容的提问来源于stack exchange,提问作者Anindya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:24:09