服务器的x.509证书,生成的签名X.509客户端证书无效(没有证书链到其CA)

public static X509Certificate2 GenerateCertificate(X509Certificate2 caCert, string certSubjectName)

{

// Generate Certificate

var cerKp = kpgen.GenerateKeyPair();

var certName = new X509Name(true,certSubjectName); // subjectName = user

var serialNo = BigInteger.ProbablePrime(120, new Random());

X509V3CertificateGenerator gen2 = new X509V3CertificateGenerator();

gen2.SetSerialNumber(serialNo);

gen2.SetSubjectDN(certName);

gen2.SetIssuerDN(new X509Name(true,caCert.Subject));

gen2.SetNotAfter(DateTime.Now.AddDays(100));

gen2.SetNotBefore(DateTime.Now.Subtract(new TimeSpan(7, 0, 0, 0)));

gen2.SetSignatureAlgorithm("SHA1WithRSA");

gen2.SetPublicKey(cerKp.Public);

AsymmetricCipherKeyPair akp = DotNetUtilities.GetKeyPair(caCert.PrivateKey);

Org.BouncyCastle.X509.X509Certificate newCert = gen2.Generate(caKp.Private);

// used for getting a private key

X509Certificate2 userCert = ConvertToWindows(newCert,cerKp);

if (caCert22.Verify()) // works well for CA

{

if (userCert.Verify()) // fails for client certificate

{

return userCert;

}

}

return null;

}

private static X509Certificate2 ConvertToWindows(Org.BouncyCastle.X509.X509Certificate newCert, AsymmetricCipherKeyPair kp)

{

string tempStorePwd = "abcd1234";

var tempStoreFile = new FileInfo(Path.GetTempFileName());

try

{

// store key

{

var newStore = new Pkcs12Store();

var certEntry = new X509CertificateEntry(newCert);

newStore.SetCertificateEntry(

newCert.SubjectDN.ToString(),

certEntry

);

newStore.SetKeyEntry(

newCert.SubjectDN.ToString(),

new AsymmetricKeyEntry(kp.Private),

new[] { certEntry }

);

using (var s = tempStoreFile.Create())

{

newStore.Save(

s,

tempStorePwd.ToCharArray(),

new SecureRandom(new CryptoApiRandomGenerator())

);

}

}

// reload key

return new X509Certificate2(tempStoreFile.FullName, tempStorePwd);

}

finally

{

tempStoreFile.Delete();

}

}

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值