You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求纯Java原生低级别代码生成内存型X509 v3证书(支持RSA及扩展)

内存中生成X509 v3 RSA证书(纯标准Java实现)

以下代码基于Java 17+标准API实现,完全符合要求:不依赖第三方库、sun内部包,仅使用JDK自带类,在内存中生成支持扩展的X509 v3 RSA证书,无需写入磁盘。

import java.math.BigInteger;
import java.security.KeyPair;
import java.security.KeyPairGenerator;
import java.security.PrivateKey;
import java.security.PublicKey;
import java.security.SecureRandom;
import java.security.cert.X509Certificate;
import java.time.Duration;
import java.time.Instant;
import java.util.List;

import javax.security.auth.x500.X500Principal;

public class InMemoryX509V3Generator {
    public static void main(String[] args) throws Exception {
        // 生成2048位RSA密钥对
        KeyPairGenerator keyPairGen = KeyPairGenerator.getInstance("RSA");
        keyPairGen.initialize(2048, new SecureRandom());
        KeyPair keyPair = keyPairGen.generateKeyPair();
        PrivateKey caPrivateKey = keyPair.getPrivate();
        PublicKey caPublicKey = keyPair.getPublic();

        // 定义证书核心字段
        X500Principal issuer = new X500Principal("CN=Self-Signed Root CA, OU=Internal, O=MyCompany, L=Beijing, ST=Beijing, C=CN");
        X500Principal subject = issuer; // 自签名证书,签发者与主体一致
        Instant notBefore = Instant.now();
        Instant notAfter = notBefore.plus(Duration.ofDays(365 * 10)); // 10年有效期
        BigInteger serialNumber = new BigInteger(64, new SecureRandom()); // 随机生成序列号

        // 构建X509 v3证书并添加扩展
        X509Certificate cert = X509Certificate.builder()
                .issuer(issuer)
                .subject(subject)
                .serialNumber(serialNumber)
                .notBefore(notBefore)
                .notAfter(notAfter)
                .publicKey(caPublicKey)
                .signatureAlgorithm("SHA256withRSA")
                // 添加Basic Constraints扩展(标记为CA,路径长度无限制)
                .addExtension("2.5.29.19", true, new byte[]{0x01, 0x01, 0xFF})
                // 添加Key Usage扩展(允许证书签名、CRL签名)
                .addExtension("2.5.29.15", true, new byte[]{0x03, 0x02, 0x05, 0x00})
                // 添加Subject Alternative Name扩展(支持多个DNS域名)
                .addExtension("2.5.29.17", false, List.of("DNS:example.com", "DNS:www.example.com"))
                // 使用私钥签名生成证书
                .sign(caPrivateKey);

        // 验证证书有效性(可选步骤)
        cert.verify(caPublicKey);
        System.out.println("证书生成成功,内存中证书信息:");
        System.out.println("证书主题:" + cert.getSubjectX500Principal());
        System.out.println("有效期:" + cert.getNotBefore() + " 至 " + cert.getNotAfter());
        System.out.println("是否包含Basic Constraints扩展:" + (cert.getExtensionValue("2.5.29.19") != null));
    }
}

关键说明:

  • 密钥生成:使用JDK标准KeyPairGenerator生成符合安全要求的2048位RSA密钥对。
  • 证书扩展:通过addExtension方法添加X509 v3标准扩展,示例包含三类常用扩展,可根据需求调整OID和扩展值。
  • 内存操作:全程仅在内存中生成X509Certificate对象,无任何磁盘写入逻辑。
  • 签名算法:采用SHA256withRSA签名算法,兼顾安全性与兼容性。

注意事项:

  • 代码依赖Java 17及以上版本,因为X509Certificate.Builder是Java 17引入的标准API,不属于sun内部包或第三方库。
  • 若需兼容Java 8/11,需手动构建ASN.1结构并完成签名,这会大幅增加代码复杂度,需借助java.security.spec和java.security.Signature手动处理证书的TBS部分与签名组装。

内容的提问来源于stack exchange,提问作者Evgeny

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.02 02:42:31