【发布时间】:2017-02-22 09:56:26
【问题描述】:
我尝试分两步创建用于测试目的的证书。首先,我创建了一个自签名证书,该证书建立了我自己的证书颁发机构 (CA)。其次,我使用该根证书签署测试服务器证书,该证书将放置在个人证书存储中。我打开一个管理命令提示符并输入以下内容:
第 1 步: MakeCert -pe -n "CN=TestCA" -b 01/01/2015 -e 01/01/2020 -ss my -sr currentuser -a sha256 -sky signature -len 2048 -r "TestCA.cer"
第 2 步: MakeCert -pe -n "CN=localhost" -b 01/01/2015 -e 01/01/2020 -eku 1.3.6.1.5.5.7.3.1 -in "TestCA" -is my -ir currentuser -ss my - sr currentuser -a sha256 -sky exchange -sp "Microsoft RSA SChannel Cryptographic Provider" -sy 12 -len 2048 "Localhost.cer"
按照这些步骤,一切正常。之后,我尝试通过 c++ 应用程序安装这些证书。当我在 certmgr.msc 中检查这些证书时似乎很好,但是,从那时起客户端总是无法连接到服务器。从个人证书存储中删除证书“localhost”后,再次使用 MakeCert.exe 执行步骤 2。客户端可以成功连接到服务器。也许我错过了一些重要的东西。如果有人知道,请给我一些建议。顺便说一句,我的客户端和服务器在同一台计算机上运行。我的代码如下所示。
HCERTSTORE hMyCertStore = NULL;
if(hMyCertStore = CertOpenStore(
CERT_STORE_PROV_SYSTEM, // The store provider type
0, // The encoding type is
// not needed
NULL, // Use the default HCRYPTPROV
CERT_SYSTEM_STORE_CURRENT_USER, // Set the store location in a
// registry location
L"MY" // The store name as a Unicode
// string
))
{
printf("The system store was created successfully.\n");
}
else
{
printf("An error occurred during creation "
"of the system store!\n");
exit(1);
}
CRYPTUI_WIZ_IMPORT_SRC_INFO importSrc;
memset(&importSrc, 0, sizeof(CRYPTUI_WIZ_IMPORT_SRC_INFO));
importSrc.dwSize = sizeof(CRYPTUI_WIZ_IMPORT_SRC_INFO);
importSrc.dwSubjectChoice = CRYPTUI_WIZ_IMPORT_SUBJECT_FILE;
importSrc.pwszFileName = L"C:\\Temp\\MakeCert\\localhost.cer";
importSrc.pwszPassword = L"";
importSrc.dwFlags = CRYPT_EXPORTABLE | CRYPT_USER_PROTECTED;
if (CryptUIWizImport(CRYPTUI_WIZ_NO_UI,
NULL,
NULL,
&importSrc,
hMyCertStore) == 0)
{
printf("CryptUIWizImport error %d\n", GetLastError());
}
任何帮助将不胜感激。
克莱门特
【问题讨论】:
标签: certificate cryptoapi