【发布时间】:2022-10-26 04:15:30
【问题描述】:
我需要将证书安装到 openshift4 pod 中 CurrentUser 的个人存储中。当我运行以下代码时,它会引发错误。
private static void InstallCertificate(string cerFileName, string friendlyName)
{
X509Store store = new X509Store(StoreName.My, StoreLocation.CurrentUser);
store.Open(OpenFlags.ReadOnly);
try
{
X509Certificate2 certificate = new X509Certificate2(cerFileName, "<<CertificatePassword>>");
if (RuntimeInformation.IsOSPlatform(OSPlatform.Windows) && !string.IsNullOrEmpty(friendlyName))
{
certificate.FriendlyName = friendlyName;
}
store.Open(OpenFlags.ReadWrite);
store.Add(certificate);
}
catch (Exception ex)
{
Console.WriteLine($"Error in adding cert: {ex.Message}");
}
store.Close();
}
代码位于 .NET 6 控制台应用程序中。此证书将用于从 OCP4 pod 连接到 MQ 所需的 SSL 身份验证。
错误信息:无法将 X509 证书添加到存储区。错误:
System.Security.Cryptography.CryptographicException: The X509 certificate could not be added to the store.
---> System.UnauthorizedAccessException: Access to the path '/.dotnet/corefx/cryptography/x509stores/my' is denied.
---> System.IO.IOException: Permission denied
--- End of inner exception stack trace ---
at System.IO.FileSystem.CreateDirectory(String fullPath)
at System.IO.Directory.CreateDirectory(String path)
at Internal.Cryptography.Pal.DirectoryBasedStoreProvider.AddCertToStore(ICertificatePal certPal)
at Internal.Cryptography.Pal.DirectoryBasedStoreProvider.Add(ICertificatePal certPal)
--- End of inner exception stack trace ---
at Internal.Cryptography.Pal.DirectoryBasedStoreProvider.Add(ICertificatePal certPal)
at System.Security.Cryptography.X509Certificates.X509Store.Add(X509Certificate2 certificate)
【问题讨论】:
-
"/.dotnet/corefx/cryptography/x509stores/my" 是什么?里面有什么?这是您的 docker 映像中的有效路径吗?还是从 Por/Deployment 挂载的某些文件? -
@titou10:这是 dotnet 核心用于将证书存储在当前用户的个人存储中的路径。这不是在 docker 映像中默认创建的。运行上述代码 sn-p 后,将创建包含证书的文件夹结构。
标签: openshift ibm-mq redhat-containers