【问题标题】:How to install x509 certificate to the Personal store Current User in Openshift4 Pod?如何将 x509 证书安装到 Openshift4 Pod 中的个人存储当前用户?
【发布时间】:2022-10-26 04:15:30
【问题描述】:

我需要将证书安装到 openshift4 pod 中 CurrentUser 的个人存储中。当我运行以下代码时,它会引发错误。

private static void InstallCertificate(string cerFileName, string friendlyName)
        {
            X509Store store = new X509Store(StoreName.My, StoreLocation.CurrentUser);
            store.Open(OpenFlags.ReadOnly);
            try
            {
                X509Certificate2 certificate = new X509Certificate2(cerFileName, "<<CertificatePassword>>");
                if (RuntimeInformation.IsOSPlatform(OSPlatform.Windows) && !string.IsNullOrEmpty(friendlyName))
                {
                    certificate.FriendlyName = friendlyName;
                }
                store.Open(OpenFlags.ReadWrite);
                store.Add(certificate);
            }
            catch (Exception ex)
            {
                Console.WriteLine($"Error in adding cert: {ex.Message}");
            }
            store.Close();
        }

代码位于 .NET 6 控制台应用程序中。此证书将用于从 OCP4 pod 连接到 MQ 所需的 SSL 身份验证。

错误信息:无法将 X509 证书添加到存储区。错误:

System.Security.Cryptography.CryptographicException: The X509 certificate could not be added to the store.
 ---> System.UnauthorizedAccessException: Access to the path '/.dotnet/corefx/cryptography/x509stores/my' is denied.
 ---> System.IO.IOException: Permission denied
   --- End of inner exception stack trace ---
   at System.IO.FileSystem.CreateDirectory(String fullPath)
   at System.IO.Directory.CreateDirectory(String path)
   at Internal.Cryptography.Pal.DirectoryBasedStoreProvider.AddCertToStore(ICertificatePal certPal)
   at Internal.Cryptography.Pal.DirectoryBasedStoreProvider.Add(ICertificatePal certPal)
   --- End of inner exception stack trace ---
   at Internal.Cryptography.Pal.DirectoryBasedStoreProvider.Add(ICertificatePal certPal)
   at System.Security.Cryptography.X509Certificates.X509Store.Add(X509Certificate2 certificate)

【问题讨论】:

  • "/.dotnet/corefx/cryptography/x509stores/my" 是什么?里面有什么?这是您的 docker 映像中的有效路径吗?还是从 Por/Deployment 挂载的某些文件?
  • @titou10:这是 dotnet 核心用于将证书存储在当前用户的个人存储中的路径。这不是在 docker 映像中默认创建的。运行上述代码 sn-p 后,将创建包含证书的文件夹结构。

标签: openshift ibm-mq redhat-containers


【解决方案1】:

我能够使用以下步骤解决问题:

  1. 添加了仅在 dockerfile 中创建 .dotnet 文件夹的命令。 (这在根目录中创建了文件夹 .dotnet。)
    RUN mkdir /.dotnet
    
    1. 添加了以下命令以提供 .dotnet 文件夹的根组权限
    RUN chgrp -R 0 /.dotnet && 
        chmod -R g=u /.dotnet 
    

    默认情况下,在 OpenShift 中启动的容器会获得一个随机用户 ID。因此,并非旨在处理此类随机 UID 的图像将因权限错误而失败。将给定命令添加到 Dockerfile 会设置目录和文件权限,以允许 root 组中的用户在构建的映像中访问它们。因为容器用户始终是根组的成员,所以容器用户可以读写这些文件。 root 组没有任何特殊权限(与 root 用户不同),因此这种安排没有安全问题。

    1. 在dockerfile中添加以上两条命令后,代码运行没有任何问题。

    我整理了所有可能对其他人有帮助的步骤!

【讨论】:

    猜你喜欢
    • 2013-05-02
    • 2019-04-20
    • 2010-09-23
    • 1970-01-01
    • 1970-01-01
    • 2019-11-08
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多