You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenSSL X509证书链验证失败,报Error 53错误求助

OpenSSL证书链验证Error 53问题解决

问题描述

持有rootca.pem、intermediate.pem和VPN_Client_Test_Certificate.pem三份证书,使用OpenSSL验证证书链时失败,报错信息如下:

C = US, ST = Colorado, L = Lakewood, O = "Cator, Ruma & Associates", OU = IT Department, CN = vpntest-client, emailAddress = dwisdom@catorruma.com
error 53 at 0 depth lookup:unsupported or invalid name syntax
VPN_Client_Test_Certificate.pem: verification failed: 53 (unsupported or invalid name syntax)

证书关键信息

rootca.pem

Certificate:
Data:
    Version: 3 (0x2)
    Serial Number:
        16:22:9f:5a:e1:95:43:9d:96:62:9a:f4:cf:55:a7:73
Signature Algorithm: sha256WithRSAEncryption
    Issuer: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=CRA External CA Root/emailAddress=dwisdom@catorruma.com
    Validity
        Not Before: Jun  4 00:00:00 2025 GMT
        Not After : Jun  5 00:00:00 2045 GMT
    Subject: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=CRA External CA Root/emailAddress=dwisdom@catorruma.com
    Subject Public Key Info:
        Public Key Algorithm: rsaEncryption
            RSA Public-Key: (4096 bit)
            
            Exponent: 65537 (0x10001)
    X509v3 extensions:
        X509v3 Authority Key Identifier: 
            keyid:18:A5:85:F6:CF:4B:13:AA:E2:FC:E3:ED:C1:9A:54:45:0E:95:32:F2

        X509v3 Subject Key Identifier: 
            18:A5:85:F6:CF:4B:13:AA:E2:FC:E3:ED:C1:9A:54:45:0E:95:32:F2
        X509v3 Basic Constraints: critical
            CA:TRUE
        X509v3 Key Usage: critical
            Digital Signature, Certificate Sign, CRL Sign

intermediate.pem

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            6a:66:10:e9:62:99:4a:af:b9:c7:d4:f9:db:aa:ab:69
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=CRA External CA Root/emailAddress=dwisdom@catorruma.com
        Validity
            Not Before: Jun  4 00:00:00 2025 GMT
            Not After : Jun  5 00:00:00 2035 GMT
        Subject: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=cra-ca.boi.cra2k.com/emailAddress=dwisdom@catorruma.com
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (4096 bit)
                Modulus:
                    
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:18:A5:85:F6:CF:4B:13:AA:E2:FC:E3:ED:C1:9A:54:45:0E:95:32:F2

            X509v3 Subject Key Identifier: 
                96:E2:E0:9C:5E:AF:6F:BC:27:DE:0C:42:67:36:B6:D4:9F:65:F2:8A
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:https://cra-ca.boi.cra2k.com/ca/revoke.crl

            X509v3 Basic Constraints: critical
                CA:TRUE, pathlen:0
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign

VPN_Client_Test_Certificate.pem

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            c1:3d:37:98:f6:25:47:b9:97:c7:b6:98:1b:89:e7:31
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=cra-ca.boi.cra2k.com/emailAddress=dwisdom@catorruma.com
        Validity
            Not Before: Jun 16 00:00:00 2025 GMT
            Not After : Jun 17 00:00:00 2026 GMT
        Subject: C=US, ST=Colorado, L=Lakewood, O=Cator, Ruma & Associates, OU=IT Department, CN=vpntest-client/emailAddress=dwisdom@catorruma.com
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:96:E2:E0:9C:5E:AF:6F:BC:27:DE:0C:42:67:36:B6:D4:9F:65:F2:8A
                DirName:/C=US/ST=Colorado/L=Lakewood/O=Cator, Ruma & Associates/OU=IT Department/CN=CRA External CA Root/emailAddress=dwisdom@catorruma.com
                serial:6A:66:10:E9:62:99:4A:AF:B9:C7:D4:F9:DB:AA:AB:69

            X509v3 Subject Key Identifier: 
                E7:04:C8:85:0A:BF:5A:F3:73:59:0B:B5:2C:6E:FA:A5:87:C6:A6:49
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:https://cra-ca.boi.cra2k.com/ca/revoke.crl

            X509v3 Basic Constraints: 
                CA:FALSE
            X509v3 Key Usage: critical
                Digital Signature, Non Repudiation, Key Encipherment
            X509v3 Extended Key Usage: 
                TLS Web Client Authentication, E-mail Protection
            X509v3 Subject Alternative Name: 
                email:localhost, email:127.0.0.1

问题原因

Error 53的核心是证书中存在不符合语法规范的名称字段,具体问题出在VPN客户端证书的X509v3 Subject Alternative Name扩展:

X509v3 Subject Alternative Name: 
    email:localhost, email:127.0.0.1

email类型的SAN必须符合RFC 5322定义的合法邮箱格式(如user@domain.com),而localhost和127.0.0.1是主机标识符,应使用DNS类型而非email类型。

解决方法

  • 重新生成客户端证书:修改证书配置文件,将SAN中的email:localhost和email:127.0.0.1改为DNS:localhost和DNS:127.0.0.1,示例配置片段:
    [req]
    req_extensions = v3_req
    
    [v3_req]
    subjectAltName = DNS:localhost, DNS:127.0.0.1, email:dwisdom@catorruma.com
    
  • 重新执行证书链验证:使用修正后的证书文件,执行以下OpenSSL命令:
    openssl verify -CAfile <(cat rootca.pem intermediate.pem) VPN_Client_Test_Certificate.pem
    

内容的提问来源于stack exchange,提问作者Karthick Balaji

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 20:24:51