OpenSSL X509证书链验证失败,报Error 53错误求助
OpenSSL证书链验证Error 53问题解决
问题描述
持有rootca.pem、intermediate.pem和VPN_Client_Test_Certificate.pem三份证书,使用OpenSSL验证证书链时失败,报错信息如下:
C = US, ST = Colorado, L = Lakewood, O = "Cator, Ruma & Associates", OU = IT Department, CN = vpntest-client, emailAddress = dwisdom@catorruma.com error 53 at 0 depth lookup:unsupported or invalid name syntax VPN_Client_Test_Certificate.pem: verification failed: 53 (unsupported or invalid name syntax)
证书关键信息
rootca.pem
Certificate: Data: Version: 3 (0x2) Serial Number: 16:22:9f:5a:e1:95:43:9d:96:62:9a:f4:cf:55:a7:73 Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=CRA External CA Root/emailAddress=dwisdom@catorruma.com Validity Not Before: Jun 4 00:00:00 2025 GMT Not After : Jun 5 00:00:00 2045 GMT Subject: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=CRA External CA Root/emailAddress=dwisdom@catorruma.com Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (4096 bit) Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Authority Key Identifier: keyid:18:A5:85:F6:CF:4B:13:AA:E2:FC:E3:ED:C1:9A:54:45:0E:95:32:F2 X509v3 Subject Key Identifier: 18:A5:85:F6:CF:4B:13:AA:E2:FC:E3:ED:C1:9A:54:45:0E:95:32:F2 X509v3 Basic Constraints: critical CA:TRUE X509v3 Key Usage: critical Digital Signature, Certificate Sign, CRL Sign
intermediate.pem
Certificate: Data: Version: 3 (0x2) Serial Number: 6a:66:10:e9:62:99:4a:af:b9:c7:d4:f9:db:aa:ab:69 Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=CRA External CA Root/emailAddress=dwisdom@catorruma.com Validity Not Before: Jun 4 00:00:00 2025 GMT Not After : Jun 5 00:00:00 2035 GMT Subject: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=cra-ca.boi.cra2k.com/emailAddress=dwisdom@catorruma.com Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (4096 bit) Modulus: Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Authority Key Identifier: keyid:18:A5:85:F6:CF:4B:13:AA:E2:FC:E3:ED:C1:9A:54:45:0E:95:32:F2 X509v3 Subject Key Identifier: 96:E2:E0:9C:5E:AF:6F:BC:27:DE:0C:42:67:36:B6:D4:9F:65:F2:8A X509v3 CRL Distribution Points: Full Name: URI:https://cra-ca.boi.cra2k.com/ca/revoke.crl X509v3 Basic Constraints: critical CA:TRUE, pathlen:0 X509v3 Key Usage: critical Digital Signature, Certificate Sign, CRL Sign
VPN_Client_Test_Certificate.pem
Certificate: Data: Version: 3 (0x2) Serial Number: c1:3d:37:98:f6:25:47:b9:97:c7:b6:98:1b:89:e7:31 Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=cra-ca.boi.cra2k.com/emailAddress=dwisdom@catorruma.com Validity Not Before: Jun 16 00:00:00 2025 GMT Not After : Jun 17 00:00:00 2026 GMT Subject: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=vpntest-client/emailAddress=dwisdom@catorruma.com Subject Public Key Info: Public Key Algorithm: rsaEncryption RSA Public-Key: (2048 bit) Modulus: Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Authority Key Identifier: keyid:96:E2:E0:9C:5E:AF:6F:BC:27:DE:0C:42:67:36:B6:D4:9F:65:F2:8A DirName:/C=US/ST=Colorado/L=Lakewood/O=Cator, Ruma & Associates/OU=IT Department/CN=CRA External CA Root/emailAddress=dwisdom@catorruma.com serial:6A:66:10:E9:62:99:4A:AF:B9:C7:D4:F9:DB:AA:AB:69 X509v3 Subject Key Identifier: E7:04:C8:85:0A:BF:5A:F3:73:59:0B:B5:2C:6E:FA:A5:87:C6:A6:49 X509v3 CRL Distribution Points: Full Name: URI:https://cra-ca.boi.cra2k.com/ca/revoke.crl X509v3 Basic Constraints: CA:FALSE X509v3 Key Usage: critical Digital Signature, Non Repudiation, Key Encipherment X509v3 Extended Key Usage: TLS Web Client Authentication, E-mail Protection X509v3 Subject Alternative Name: email:localhost, email:127.0.0.1
问题原因
Error 53的核心是证书中存在不符合语法规范的名称字段,具体问题出在VPN客户端证书的X509v3 Subject Alternative Name扩展:
X509v3 Subject Alternative Name: email:localhost, email:127.0.0.1
email类型的SAN必须符合RFC 5322定义的合法邮箱格式(如user@domain.com),而localhost和127.0.0.1是主机标识符,应使用DNS类型而非email类型。
解决方法
- 重新生成客户端证书:修改证书配置文件,将SAN中的
email:localhost和email:127.0.0.1改为DNS:localhost和DNS:127.0.0.1,示例配置片段:[req] req_extensions = v3_req [v3_req] subjectAltName = DNS:localhost, DNS:127.0.0.1, email:dwisdom@catorruma.com - 重新执行证书链验证:使用修正后的证书文件,执行以下OpenSSL命令:
openssl verify -CAfile <(cat rootca.pem intermediate.pem) VPN_Client_Test_Certificate.pem
内容的提问来源于stack exchange,提问作者Karthick Balaji
相关产品推荐
相关产品推荐

