使用asn1crypto与pkcs11操作Aladdin USB eToken时信任链不显示问题
Let’s break down what’s happening here and how to fix it:
Your current code is generating a brand new self-signed certificate using the private key from your eToken—but it’s not using any of the existing certificates (your issued end-entity cert, intermediate CA certs) that are stored on the token provided by your CA. That’s why when you paste the PEM into asn1js, you only see this single self-signed cert—there’s no trust chain included.
The eToken from your CA should already contain the full trust chain (your end-entity certificate + intermediate CA certificates, possibly the root CA). Instead of creating a new cert, you need to retrieve these existing certificates from the token and export them as a combined PEM chain.
Corrected Code to Export the Existing Trust Chain
Here’s how to modify your code to fetch and export the complete certificate chain from your eToken:
import pkcs11 from pkcs11.constants import ObjectClass, Attribute import pem # Load the eToken library lib = pkcs11.lib('/usr/lib/libeToken.so.9') for slot in lib.get_slots(): try: token = slot.get_token() with token.open(user_pin='****') as session: # Retrieve all certificates stored on the token cert_objects = session.get_objects({ Attribute.CLASS: ObjectClass.CERTIFICATE }) # Collect DER-encoded certificate data certificate_chain = [] for cert in cert_objects: der_data = cert[Attribute.VALUE] certificate_chain.append(der_data) # Convert each DER cert to PEM and combine into a single chain pem_chain = b"" for der in certificate_chain: pem_chain += pem.armor('CERTIFICATE', der) print(pem_chain.decode()) except pkcs11.exceptions.TokenNotPresent: pass
Key Details:
- Retrieve Existing Certs: This code fetches all certificates stored on your eToken instead of generating a new one. These are the actual certificates issued to you by the CA, along with the intermediate CA certs needed for the trust chain.
- Chain Order: For most systems, order the chain with your end-entity certificate first, followed by intermediate CA certificates (from lowest to highest in the chain). Root CAs are typically trusted by the system itself and don’t need to be included.
- Sorting (If Needed): If your token stores certs in an unordered way, you can add logic to sort them using attributes like
Attribute.SUBJECTandAttribute.ISSUER—the issuer of one cert should match the subject of the next in the chain.
Why Your Original Code Failed
Your original code built a new certificate from scratch, setting dummy values like issuer and subject to "Test Certificate". This creates a self-signed cert with no connection to your CA’s trust chain. The private key from the eToken only signed this new cert, but the cert itself isn’t part of the CA’s issued chain.
By exporting the existing certificates from the eToken, you’ll get the correct chain that asn1js will recognize and display properly.
内容的提问来源于stack exchange,提问作者Fellipe Theophilo Barata

