【发布时间】:2020-05-21 17:12:46
【问题描述】:
我正在尝试为本地开发设置 https 服务器。我正在使用 Windows 10 机器。我已经使用 openssl 生成了一个自签名证书。我使用了以下命令。
openssl genrsa -out key.pem
openssl req -new -key key.pem -out csr.pem
openssl x509 -req -days 9999 -in csr.pem -signkey key.pem -out cert.pem
rm csr.pem
这是输出“hello world”的演示服务器代码(NodeJS)。
const https = require('https');
const fs = require('fs');
const options = {
key: fs.readFileSync('key.pem'),
cert: fs.readFileSync('cert.pem')
};
https.createServer(options, function (req, res) {
res.writeHead(200);
res.end("hello world\n");
}).listen(8000);
我已经使用 curl 命令从命令提示符访问了 URL
curl https://localhost:8000
我得到的错误是
curl: (35) schannel: SNI or certificate check failed: SEC_E_WRONG_PRINCIPAL (0x80090322) - The target principal name is incorrect.
我已使用“Microsoft 管理控制台 (mmc)”在“受信任的根证书颁发机构”存储中添加了自签名证书。这是我的 Certificate image.
我不明白我哪里出错了。请帮我解决这个问题。
【问题讨论】:
-
(1) 这不是一个编程或开发问题或问题——尽管我没有像我期望的那样在 SU 或 SF 上找到一个骗子 (2) 证书中的 CommonName = CN (或 SubjectAlternativeName = SAN 如果使用,您的简单 OpenSSL 没有)必须与 URL 中用于访问服务器的名称匹配,即如果您使用
https://localhost:port,CN 必须是localhost(注意没有端口)
标签: openssl ssl-certificate x509 mmc