PKI.js V2添加CSR主体备用名称(SAN)失败求助
I have a fully functional implementation based on PKI.js V1 and the WebCrypto API that successfully adds DNS-type Subject Alternative Names (SAN) to Certificate Signing Requests (CSRs) without any issues. However, when trying to replicate this functionality in PKI.js V2, the code fails to work as expected, and I'm struggling to pinpoint the root cause.
Background on Working V1 Setup
- I used the CSRhelp sample project (which doesn't include SAN support by default)
- After replacing the code at line 516 in
csrhelp-master\app\src\csrhelps\CsrhelpService.js, the SAN addition worked perfectly.
Broken V2 Setup
- I'm using the PKCS#10 complex sample project for V2
- After modifying the code at line 16784 in
PKCS10_complex_example.js, the functionality breaks entirely.
Key Troubleshooting Areas to Check
Since PKI.js V2 introduced significant API refactoring compared to V1, here are the most likely issues and fixes to investigate:
Adapt to V2's API Structure
PKI.js V2 overhauled how extensions like SAN are constructed and attached to CSRs. The V1 approach won't directly translate. Ensure your code follows V2's pattern for building SAN extensions:// Create SAN extension with DNS entries const san = new pkijs.SubjectAlternativeName(); san.names = [ new pkijs.GeneralName({ type: 2, value: "your-domain.com" }), new pkijs.GeneralName({ type: 2, value: "www.your-domain.com" }) ]; // Wrap SAN as a CSR extension const sanExtension = new pkijs.Extension({ extnID: "2.5.29.17", // OID for Subject Alternative Name critical: false, extnValue: san.toSchema().toBER(false) }); // Add extension request to CSR attributes if (!csr.attributes) csr.attributes = []; csr.attributes.push(new pkijs.Attribute({ type: "1.2.840.113549.1.9.14", // Extension Request OID values: [new pkijs.Extensions({ extensions: [sanExtension] })] }));Verify that your modified code aligns with this structure, rather than reusing V1's old method calls.
Confirm You're Modifying the Correct Code Line
Line numbers in minified/concatenated files likePKCS10_complex_example.jscan vary depending on the exact version of the sample. Double-check that line 16784 is indeed the section where CSR extensions are being constructed or added—if not, you might be modifying unrelated code.Check for Console Errors
Open your browser's developer tools and check the console for any uncaught exceptions or warning messages. PKI.js V2 provides more detailed error logging for issues like invalid extension encoding, incorrect OIDs, or missing required fields, which can quickly point you to the problem.Validate WebCrypto Interoperability
While the WebCrypto API itself is largely consistent, PKI.js V2 has stricter requirements for key formats and algorithm parameters. Ensure your key generation and signing workflow is compatible with V2's expectations (e.g., correct key usages, proper algorithm identifiers).
If you can share the exact code snippet you're replacing in the V2 sample, along with any console error messages, it'll be much easier to diagnose the issue precisely.
内容的提问来源于stack exchange,提问作者Anindya

