【问题标题】:curl: (35) schannel: SNI or certificate check failed: SEC_E_WRONG_PRINCIPAL (0x80090322) - The target principal name is incorrectcurl:(35)schannel:SNI或证书检查失败:SEC_E_WRONG_PRINCIPAL(0x80090322)-目标主体名称不正确
【发布时间】:2020-05-21 17:12:46
【问题描述】:

我正在尝试为本地开发设置 https 服务器。我正在使用 Windows 10 机器。我已经使用 openssl 生成了一个自签名证书。我使用了以下命令。

openssl genrsa -out key.pem
openssl req -new -key key.pem -out csr.pem
openssl x509 -req -days 9999 -in csr.pem -signkey key.pem -out cert.pem
rm csr.pem

这是输出“hello world”的演示服务器代码(NodeJS)。

const https = require('https');
const fs = require('fs');

const options = {
  key: fs.readFileSync('key.pem'),
  cert: fs.readFileSync('cert.pem')
};


https.createServer(options, function (req, res) {
  res.writeHead(200);
  res.end("hello world\n");
}).listen(8000);

我已经使用 curl 命令从命令提示符访问了 URL

curl https://localhost:8000

我得到的错误是

curl: (35) schannel: SNI or certificate check failed: SEC_E_WRONG_PRINCIPAL (0x80090322) - The target principal name is incorrect.

我已使用“Microsoft 管理控制台 (mmc)”在“受信任的根证书颁发机构”存储中添加了自签名证书。这是我的 Certificate image.

我不明白我哪里出错了。请帮我解决这个问题。

【问题讨论】:

  • (1) 这不是一个编程或开发问题或问题——尽管我没有像我期望的那样在 SU 或 SF 上找到一个骗子 (2) 证书中的 CommonName = CN (或 SubjectAlternativeName = SAN 如果使用,您的简单 OpenSSL 没有)必须与 URL 中用于访问服务器的名称匹配,即如果您使用 https://localhost:port,CN 必须是 localhost(注意没有端口)

标签: openssl ssl-certificate x509 mmc


【解决方案1】:

您还可以使用带有 CURL 的 -k 开关来忽略 SSL 证书错误。显然,对于要确保证书良好的环境,不建议这样做。

【讨论】:

    【解决方案2】:

    您的证书中的通用名称 (CN) 是“我自己的数字证书”,而它应该是“localhost”。重新创建 CSR 并像这样显式设置 CN

    openssl req -new -key key.pem -subj "/CN=localhost" -out csr.pem
    

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2020-11-15
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多