You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用OpenSSL API添加自定义扩展的X509v3证书CSR签发问题

Hey there! Let’s walk through your OpenSSL code for adding a custom extension to a CSR, and go over some key points to refine it, plus notes on what might be going on with your issued certificate.

Breakdown & Improvements to Your Code

First off, your core approach is solid—you’re creating a custom OID, building the extension, and attaching it to the CSR. Here are some tweaks to make it more robust:

  • Fix Memory Leaks: OpenSSL doesn’t handle automatic garbage collection, so you’re leaving several objects hanging around after use. Add cleanup code once you’re done with the extension stack and string:

    // After calling X509_REQ_add_extensions(x, exts);
    sk_X509_EXTENSION_pop_free(exts, X509_EXTENSION_free);
    ASN1_OCTET_STRING_free(os);
    

    This prevents memory leaks, especially if your code runs repeatedly (like in a service).

  • Avoid Duplicate OID Registration: Using OBJ_create() registers the OID globally. If your code runs multiple times, this will throw an error when trying to re-register the same OID. Check if it exists first:

    int nid = OBJ_txt2nid("CompanyName");
    if (nid == NID_undef) {
        // Only create if it doesn't already exist
        nid = OBJ_create("2.5.29.41", "CompanyName", "Company Name");
    }
    

    Also, a quick heads-up: the 2.5.29 arc is for standard X.509 extensions. Using an unassigned OID here might cause validation issues down the line—make sure you have the right to use this OID for your organization.

  • Safer String Length: You hardcoded 8 for "ABC Corp"’s length, which works now, but it’s easy to break if you change the company name later. Use strlen() instead:

    ASN1_OCTET_STRING_set(os, "ABC Corp", strlen("ABC Corp"));
    
  • Critical Extension Flag: You set the crit parameter to 0 (non-critical) in X509_EXTENSION_create_by_NID(). That’s totally fine unless you need relying parties to process this extension—if you do, flip that to 1.

Notes on Your Issued Certificate

Since you’ve already received the signed certificate, the good news is your CSR was processed correctly! If you’re noticing the custom extension is missing from the final cert, it’s likely the CA’s policy strips unrecognized non-critical extensions. You’ll need to check with your CA to see if they support including custom extensions, or if you need to submit a request to enable that.

内容的提问来源于stack exchange,提问作者Ajay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:50:55