FreeIPA证书续订时主体名称编码不匹配问题及CSR字段编码转换实操求助
我最近在处理FreeIPA的证书续订工作,CA用的是Windows系统,过程中碰到了一堆和编码相关的棘手问题,想请大家帮忙支支招:
背景情况
之前为了让Windows签发的证书主体名称采用UTF8编码,特意放弃了GUI操作,改用Windows命令行来签发证书,本以为这就解决了编码问题,结果后续操作又卡壳了。
第一次报错:证书链不完整
我执行这条命令导入续订的CA证书链:
ipa-cacert-manage renew --external-cert-file=./freeipaca-windows-commandline.pem --external-cert-file=./cachain.pem
得到的报错是:
Importing the renewed CA certificate, please wait
CA certificate chain in ./freeipaca-windows-commandline.pem, ./cachain.pem is incomplete: missing certificate with subject 'CN=example.com ICA Windows-CA,DC=example,DC=com'
我怀疑问题出在证书链的编码上——之前主体字段的编码问题就是靠命令行签发解决的,现在证书链里的commonName字段用的是PRINTABLESTRING而非UTF8。我用openssl命令验证了编码情况:
openssl x509 -in cachain.pem -subject -issuer -nameopt multiline,show_type -noout
输出结果如下:
subject=
domainComponent = IA5STRING:com
domainComponent = IA5STRING:example
domainComponent = IA5STRING:internal
commonName = PRINTABLESTRING:internal.example.com ICA Windows-CA2
issuer=
commonName = PRINTABLESTRING:example.com Root CA Windows-CA1
关于编码转换的疑惑
之前看到有讨论说可以修改CSR里的字段编码(比如从UTF8改成Printable String),但我是反过来的需求:要把PRINTABLESTRING改成UTF8。我完全搞不懂该怎么定位到要编辑的对应值,而且看到有人把十六进制值列成竖排,这是我在十六进制编辑器里该找的格式吗?我用的是Hexer,因为熟悉vi的操作逻辑,但对Hexer本身的用法不太熟悉。
后续更新:原问题未解决
结果发现之前用命令行签发证书的方法根本没解决问题!FreeIPA 4.6.8依然报错:
ipa-cacert-manage renew --external-cert-file=./cert_and_chain.pem
报错内容:
Importing the renewed CA certificate, please wait
Subject name encoding mismatch (visit http://www.freeipa.org/page/Troubleshooting for troubleshooting guide)
The ipa-cacert-manage command failed.
再次用openssl查看证书,发现主体和签发者的commonName还是PRINTABLESTRING编码:
openssl x509 -in cert_and_chain.pem -subject -issuer -nameopt multiline,show_type -noout
输出:
subject=
organizationName = PRINTABLESTRING:EXAMPLE.NET
commonName = PRINTABLESTRING:Certificate Authority
issuer=
domainComponent = IA5STRING:com
domainComponent = IA5STRING:example
commonName = PRINTABLESTRING:example.com ICA Windows-CA
求助问题
想请教大家两个问题:
- 有没有更简单的办法绕过这个编码不匹配的问题?
- 如果必须修改编码的话,怎么用Hexer找到对应的字段,把PRINTABLESTRING改成UTF8呢?
备注:内容来源于stack exchange,提问作者Sapg

