【问题标题】:Cannot get any results with Net::SSLeay for openssl使用 Net::SSLeay for openssl 无法获得任何结果
【发布时间】:2015-03-24 18:35:13
【问题描述】:

我正在尝试创建一个脚本来查看我的 ~/ssl/certs 文件夹中的证书数据并向我显示颁发者信息。

它是用 perl 编写的,很容易说:

$data = `/usr/bin/openssl x509 -in $file -noout -issuer`

但是,这不是很便携。我正在尝试使用 Net::SSLeay 来获得相同的输出,但是我似乎只能管理校验和数字,我错过了什么?这是我得到的

#!/usr/bin/perl
use 5.10.1;
use strict;
use warnings;
use Net::SSLeay qw(die_now die_if_ssl_error);
Net::SSLeay::load_error_strings();
Net::SSLeay::SSLeay_add_ssl_algorithms();    # Important!
Net::SSLeay::ENGINE_load_builtin_engines();  # If you want built-in engines
Net::SSLeay::ENGINE_register_all_complete(); # If you want built-in engines
Net::SSLeay::randomize();
Net::SSLeay::library_init();
Net::SSLeay::OpenSSL_add_all_algorithms();
my $file = '~/ssl/certs/certificate.crt';

my $x509 = Net::SSLeay::X509_new(); 
Net::SSLeay::X509_free($x509);
my $type = Net::SSLeay::X509_certificate_type($x509);
my $ctx = Net::SSLeay::CTX_new_with_method(Net::SSLeay::TLSv1_method());
my $test = Net::SSLeay::X509_load_cert_file( $ctx, $file, $type );
my $info = Net::SSLeay::X509_issuer_name_hash($x509);

say "\nInfo = $info \nX509 = $x509\nTest= $test\nType = $type\nCTX = $ctx";



This is my output:
Info = 4003674586 
X509 = 16119648
Test= 0
Type = 0
CTX = 16137888

我已经阅读了所有的源代码和文档,没有任何意义。

【问题讨论】:

    标签: perl ssl openssl x509


    【解决方案1】:

    您不需要所有这些上下文等。初始化 SSL 库后,您可以简单地执行以下操作:

    my $bio = Net::SSLeay::BIO_new_file($file,'r') or die $!;
    my $cert = Net::SSLeay::PEM_read_bio_X509($bio);
    Net::SSLeay::BIO_free($bio);
    $cert or die "cannot parse $file as PEM X509 cert: ".
        Net::SSLeay::ERR_error_string(Net::SSLeay::ERR_get_error());
    my $issuer = Net::SSLeay::X509_NAME_oneline(
        Net::SSLeay::X509_get_issuer_name($cert));
    

    【讨论】:

    • 非常感谢!效果很好,他们确实需要更好地解释他们的文档。
    • @Jeffrey:Net::SSLeay 是免费软件,根据我的经验,维护者对改进软件的更改非常开放。因此,请随时提供使文档更好的补丁。
    • 是否可以完全解码 base64 版本的证书或密钥并打印数据?似乎您只能打印主题、颁发者和很少的其他内容。我正在尝试比较密钥和证书的模数以确保它们匹配
    • 查看 OpenSSL apps/x509.c 的源代码我会说模数只能通过访问内部结构而不是 API 函数来获得。因此,您可能无法通过 Net::SSLeay 函数获得它。
    【解决方案2】:

    这个例子也许能让你开始:

    https://metacpan.org/source/MIKEM/Net-SSLeay-1.68/examples/x509_cert_details.pl

    我已经从中剪掉了相关的部分,只是为了得到发行人:

    #!/usr/bin/perl
    
    use strict;
    use warnings;
    
    use Net::SSLeay qw/XN_FLAG_RFC2253 ASN1_STRFLGS_ESC_MSB/;
    
    Net::SSLeay::randomize();
    Net::SSLeay::load_error_strings();
    Net::SSLeay::ERR_load_crypto_strings();
    Net::SSLeay::SSLeay_add_ssl_algorithms();
    
    my $file = shift;
    chomp($file);
    
    my $bio = Net::SSLeay::BIO_new_file($file, 'rb') or die "ERROR: BIO_new_file failed";
    my $x509 = Net::SSLeay::PEM_read_bio_X509($bio) or die "ERROR: PEM_read_bio_X509 failed";
    
    my $issuer_name = Net::SSLeay::X509_get_issuer_name($x509);
    print Net::SSLeay::X509_NAME_print_ex($issuer_name) . "\n";
    

    那么:

    $ perl ssl.pl /usr/share/ca-certificates/mozilla/XRamp_Global_CA_Root.crt
    CN=XRamp Global Certification Authority,O=XRamp Security Services Inc,OU=www.xrampsecurity.com,C=US
    

    【讨论】:

      猜你喜欢
      • 2015-01-31
      • 2019-03-24
      • 1970-01-01
      • 1970-01-01
      • 2017-11-02
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2020-04-01
      相关资源
      最近更新 更多