【问题标题】:Get x509 certificate hash with openssl library使用 openssl 库获取 x509 证书哈希
【发布时间】:2015-05-05 17:06:30
【问题描述】:

我目前正在开发一个应用程序,它使用 openssl 库 (libcrypto) 来生成证书。现在我必须得到一个已经存在的证书的哈希值。

当我使用终端时,我可以使用

生成哈希值
openssl x509 -hash -in cert.pem -noout

输出:01da0e2b

这是我的代码,我尝试使用 C 中的库生成哈希值。

X509 *cert = NULL;
FILE *fp = fopen(currentCert.UTF8String, "r");
PEM_read_X509(fp, &cert, NULL, NULL);

long hash = X509_subject_name_hash(cert);
char *mdString = malloc(sizeof(long));
sprintf(mdString, "%lx",hash);
printf(mdString);

输出:1817886a

但实际上我的输出是不同的。有人知道我在做什么错吗?

【问题讨论】:

  • 只用printf("0x%08lx",hash),不明白是什么原因将其序列化为char *,这也是不正确的,因为缓冲区的大小应该取决于位数

标签: c hash openssl x509 libcrypto


【解决方案1】:

但实际上我的输出是不同的。有人知道我在做什么错吗?

OpenSSL 是如何使用它的...

$ cd openssl-1.0.2-src
$ grep -R X509_subject_name_hash *
apps/x509.c:                BIO_printf(STDout, "%08lx\n", X509_subject_name_hash(x));
apps/x509.c:                BIO_printf(STDout, "%08lx\n", X509_subject_name_hash_old(x));
crypto/x509/x509.h:unsigned long X509_subject_name_hash(X509 *x);
crypto/x509/x509.h:unsigned long X509_subject_name_hash_old(X509 *x);
crypto/x509/x509_cmp.c:unsigned long X509_subject_name_hash(X509 *x)
crypto/x509/x509_cmp.c:unsigned long X509_subject_name_hash_old(X509 *x)
...

然后,看着apps/x509.c:

...
} else if (subject_hash == i) {
    BIO_printf(STDout, "%08lx\n", X509_subject_name_hash(x));
}
...

你的声明应该是:

unsigned long hash = X509_subject_name_hash(cert);

然后:

fprintf(stdout, "%08lx\n", hash);

此外,OpenSSL 在 OpenSSL 1.0.1 前后的某个时候改变了计算主题哈希的方式。这就是为什么会有X509_subject_name_hash 和X509_subject_name_hash_old。

如果您正在使用 OpenSSL 0.9.8 或与之比较(例如 Mac OS X 10),请参阅 Generate Subject Hash of X509Certificate in Java。虽然它是 Java,但它详细说明了主题哈希的 OpenSSL 处理。

【讨论】:

  • 是的,这行得通。实际上我发现,服务器使用的是旧的 openssl 库。所以我不得不使用 X509_subject_name_hash_old(cert);谢谢你的回答!
【解决方案2】:

您没有为字符串分配足够的内存,尽管我不能确定这是您问题的原因。

char *mdString = malloc(sizeof(long));

将为字符串分配 4 个字节,但它显然需要保存 8 个字节加上一个终止符,所以我建议

char *mdString = malloc(sizeof(long)*2 + 1);

【讨论】:

  • 我认为你是对的,但是,实际上我得到了相同的输出。 "1817886a"
猜你喜欢
  • 2021-02-17
  • 1970-01-01
  • 2020-02-04
  • 1970-01-01
  • 2018-11-24
  • 2016-06-07
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多