亚洲香蕉成人av网站在线观看_欧美精品成人91久久久久久久_久久久久久久久久久亚洲_热久久视久久精品18亚洲精品_国产精自产拍久久久久久_亚洲色图国产精品_91精品国产网站_中文字幕欧美日韩精品_国产精品久久久久久亚洲调教_国产精品久久一区_性夜试看影院91社区_97在线观看视频国产_68精品久久久久久欧美_欧美精品在线观看_国产精品一区二区久久精品_欧美老女人bb

首頁 > 學院 > 開發設計 > 正文

用OpenSSL創建CA和簽發證書,轉換成java可以加載的jks

2019-11-14 10:21:52
字體:
來源:轉載
供稿:網友

java的keytool工具本來就可以生成交互式認證的證書, 不過其他語言處理交互式認證的流程貌似和java的keytool的認證流程有些差別,  而openssl是比較通用的工具。大部分語言都會支持openssl生成的證書文件。用openssl簽發的證書如何才能轉化為keytool的jks文件呢,  就需要用到 ImportKey.java 文件的源碼來處理了。

 - CAserial 指明序列號文件,而 - CAcreateserial 指明文件不存在時自動生成

 所有證書的Common Name 也就是CN不能重復

----------------------------------START--------------------------------CA根證書openssl genrsa -out ca.key 2048openssl req -x509 -new -nodes -key ca.key -subj "/CN=ABC" -days 36500 -out ca.crtopenssl pkcs12 -export -clcerts -in ./ca.crt -inkey ca.key -out ca.p12服務器端:openssl genrsa -out Xserver.key 2048openssl req -new -key Xserver.key -subj "/CN=DEF" -out Xserver.csropenssl x509 -req -days 36500 -in Xserver.csr -CA ca.crt -CAkey ca.key -CAcreateserial  -out Xserver.crtcp  Xserver.key  Xserver.key.pemcp  Xserver.crt  Xserver.crt.pemopenssl pkcs8 -topk8 -nocrypt -in Xserver.key.pem -inform PEM -out Xserver.key.der -outform DER openssl x509 -in Xserver.crt.pem -inform PEM -out Xserver.crt.der -outform DER 生成 jks文件給java程序使用java -jar  OpenSSL2JKS.jar  Xserver.key.der   Xserver.crt.der  123456  ./server.keystore server_jks創建信任列表keytool -import -v -alias rootca -keystore ./serverTrust.jks -storepass 123456  -trustcacerts -file ./ca.crt keytool -import -v -alias server -keystore ./serverTrust.jks -storepass 123456  -trustcacerts -file ./client.services-ca.pem生成瀏覽器證書openssl genrsa -out XBrowser.key 2048openssl req -new -key XBrowser.key -subj "/CN=XXX" -out XBrowser.csropenssl x509 -req -days 36500 -in XBrowser.csr -CA ca.crt -CAkey ca.key -CAcreateserial  -out XBrowser.crt把瀏覽器證書轉化為PKCS12格式openssl pkcs12 -export -clcerts -in ./XBrowser.crt -inkey XBrowser.key -out XBrowser.p12用openssl自帶的工具進行測試openssl s_client -connect www.tesladevel.com:9999 -cert ./XBrowser.crt -key ./XBrowser.key  -tls1 -CAfile ./ca.crt  -state -showcerts------------------------------------------END--------------------------------------------------

上面用到的  OpenSSL2JKS.jar , 其實是  ImportKey.java 文件 ,

下載地址如下:

www.agentbob.info/agentbob/80/version/default/part/AttachmentData/data/ImportKey.java

我把這個文件的源碼貼出來:

package com.tool;import java.security.*;import java.io.IOException;import java.io.InputStream;import java.io.FileInputStream;import java.io.DataInputStream;import java.io.ByteArrayInputStream;import java.io.FileOutputStream;import java.security.spec.*;import java.security.cert.Certificate;import java.security.cert.CertificateFactory;import java.util.Collection;import java.util.Iterator;/** * ImportKey.java * * <p>This class imports a key and a certificate into a keystore * (<code>$home/keystore.ImportKey</code>). If the keystore is * already PResent, it is simply deleted. Both the key and the * certificate file must be in <code>DER</code>-format. The key must be * encoded with <code>PKCS#8</code>-format. The certificate must be * encoded in <code>X.509</code>-format.</p> * * <p>Key format:</p> * <p><code>openssl pkcs8 -topk8 -nocrypt -in YOUR.KEY -out YOUR.KEY.der * -outform der</code></p> * <p>Format of the certificate:</p> * <p><code>openssl x509 -in YOUR.CERT -out YOUR.CERT.der -outform * der</code></p> * <p>Import key and certificate:</p> * <p><code>java comu.ImportKey YOUR.KEY.der YOUR.CERT.der</code></p><br /> * * <p><em>Caution:</em> the old <code>keystore.ImportKey</code>-file is * deleted and replaced with a keystore only containing <code>YOUR.KEY</code> * and <code>YOUR.CERT</code>. The keystore and the key has no passWord;  * they can be set by the <code>keytool -keypasswd</code>-command for setting * the key password, and the <code>keytool -storepasswd</code>-command to set * the keystore password. * <p>The key and the certificate is stored under the alias * <code>importkey</code>; to change this, use <code>keytool -keyclone</code>. * * Created: Fri Apr 13 18:15:07 2001 * Updated: Fri Apr 19 11:03:00 2002 * * @author Joachim Karrer, Jens Carlberg * @version 1.1 **/public class ImportKey  {        /**     * <p>Creates an InputStream from a file, and fills it with the complete     * file. Thus, available() on the returned InputStream will return the     * full number of bytes the file contains</p>     * @param fname The filename     * @return The filled InputStream     * @exception IOException, if the Streams couldn't be created.     **/    private static InputStream fullStream ( String fname ) throws IOException {        FileInputStream fis = new FileInputStream(fname);        DataInputStream dis = new DataInputStream(fis);        byte[] bytes = new byte[dis.available()];        dis.readFully(bytes);        ByteArrayInputStream bais = new ByteArrayInputStream(bytes);        return bais;    }            /**     * <p>Takes two file names for a key and the certificate for the key,      * and imports those into a keystore. Optionally it takes an alias     * for the key.     * <p>The first argument is the filename for the key. The key should be     * in PKCS8-format.     * <p>The second argument is the filename for the certificate for the key.     * <p>If a third argument is given it is used as the alias. If missing,     * the key is imported with the alias importkey     * <p>The name of the keystore file can be controlled by setting     * the keystore property (java -Dkeystore=mykeystore). If no name     * is given, the file is named <code>keystore.ImportKey</code>     * and placed in your home directory.     * @param args [0] Name of the key file, [1] Name of the certificate file     * [2] Alias for the key.     **/    public static void main ( String args[]) {                // change this if you want another password by default        String keypass = "importkey";                // change this if you want another alias by default        String defaultalias = "importkey";        // change this if you want another keystorefile by default        String keystorename = System.getProperty("keystore");        if (keystorename == null)            keystorename = System.getProperty("user.home")+  System.getProperty("file.separator")+ "keystore.ImportKey"; // especially this ;-)        // parsing command line input        String keyfile = "";        String certfile = "";        if (args.length < 2 || args.length>5) {            System.out.println("Usage: java comu.ImportKey keyfile certfile keypass keystorename [alias]");            System.exit(0);        } else {            keyfile = args[0];            certfile = args[1];            keypass = args[2];            keystorename = args[3];                        if (args.length>4)                defaultalias = args[4];        }        try {            // initializing and clearing keystore             KeyStore ks = KeyStore.getInstance("JKS", "SUN");            ks.load( null , keypass.toCharArray());            System.out.println("Using keystore-file : "+keystorename);            ks.store(new FileOutputStream ( keystorename  ),  keypass.toCharArray());            ks.load(new FileInputStream ( keystorename ),  keypass.toCharArray());            // loading Key            InputStream fl = fullStream (keyfile);            byte[] key = new byte[fl.available()];            KeyFactory kf = KeyFactory.getInstance("RSA");            fl.read ( key, 0, fl.available() );            fl.close();            PKCS8EncodedKeySpec keysp = new PKCS8EncodedKeySpec ( key );            PrivateKey ff = kf.generatePrivate (keysp);            // loading CertificateChain            CertificateFactory cf = CertificateFactory.getInstance("X.509");            InputStream certstream = fullStream (certfile);            Collection c = cf.generateCertificates(certstream) ;            Certificate[] certs = new Certificate[c.toArray().length];            if (c.size() == 1) {                certstream = fullStream (certfile);                System.out.println("One certificate, no chain.");                Certificate cert = cf.generateCertificate(certstream) ;                certs[0] = cert;            } else {                System.out.println("Certificate chain length: "+c.size());                certs = (Certificate[])c.toArray();            }            // storing keystore            ks.setKeyEntry(defaultalias, ff, keypass.toCharArray(), certs );            System.out.println ("Key and certificate stored.");            System.out.println ("Alias:"+defaultalias+"  Password:"+keypass);            ks.store(new FileOutputStream ( keystorename ), keypass.toCharArray());        } catch (Exception ex) {            ex.printStackTrace();        }    }}// KeyStore

Import private key and certificate into Java Key Store (JKS)

Apache Tomcat and many other Java applications expect to retrieve SSL/TLScertificates from a Java Key Store (JKS). Jave Virtual Machines usually comewithkeytool to help you create a new key store.

Keytool helps you to:

create a new JKS with a new private keygenerate a Certificate Signung Request (CSR) for the private key in this JKSimport a certificate that you received for this CSR into your JKS

Keytool does not let you import an existing private key forwhich you already have a certificate. So you need to do this yourself, here'show:

Let's assume you have a private key (key.pem) and acertificate (cert.pem), both in PEM format as the file namessuggest.

PEM format is 'kind-of-human-readable' and looks like e.g.

-----BEGIN CERTIFICATE-----Ulv6GtdFbjzLeqlkelqwewlq822OrEPdH+zxKUkKGX/eN.. (snip).9801asds3BCfu52dm7JHzPAOqWKaEwIgymlk=----END CERTIFICATE-----

Convert both, the key and the certificate into DER format usingopenssl :

openssl pkcs8 -topk8 -nocrypt -in key.pem -inform PEM -out key.der -outform DERopenssl x509 -in cert.pem -inform PEM -out cert.der -outform DER

Now comes the tricky bit, you need something to import these files into theJKS. ImportKey will do this for you, get theImportKey.java (text/x-java-source, 6.6 kB, info) source or the compiled (Java 1.5 !)ImportKey.class (application/octet-stream, 3.3 kB, info) and run it like

user@host:~$ java ImportKey key.der cert.derUsing keystore-file : /home/user/keystore.ImportKeyOne certificate, no chain.Key and certificate stored.Alias:importkey  Password:importkey

Now we have a proper JKS containing our private key and certificate in a filecalled keystore.ImportKey, using 'importkey' as alias and also as password. Forany further changes, like changing the password we can use keytool.

http://stackoverflow.com/questions/723368/how-to-use-pem-file-to-create-a-ssl-socket-in-java


發表評論 共有條評論
用戶名: 密碼:
驗證碼: 匿名發表
亚洲香蕉成人av网站在线观看_欧美精品成人91久久久久久久_久久久久久久久久久亚洲_热久久视久久精品18亚洲精品_国产精自产拍久久久久久_亚洲色图国产精品_91精品国产网站_中文字幕欧美日韩精品_国产精品久久久久久亚洲调教_国产精品久久一区_性夜试看影院91社区_97在线观看视频国产_68精品久久久久久欧美_欧美精品在线观看_国产精品一区二区久久精品_欧美老女人bb
欧美第一页在线| 国产a∨精品一区二区三区不卡| 色老头一区二区三区在线观看| 国产精品久久电影观看| 精品久久久久人成| 97视频在线观看免费高清完整版在线观看| 欧美日韩国产一中文字不卡| 欧美人与性动交a欧美精品| 91av视频在线播放| 成人黄色免费片| 91精品国产综合久久久久久久久| 美女视频黄免费的亚洲男人天堂| 亚洲男人天堂久| 亚洲一区第一页| 国产欧美va欧美va香蕉在| 国产噜噜噜噜久久久久久久久| 亚洲精品视频播放| 亚洲精品久久久久国产| 97成人精品视频在线观看| 一本色道久久88综合亚洲精品ⅰ| 在线精品国产成人综合| 97国产精品视频人人做人人爱| 91日韩在线视频| 亚洲韩国欧洲国产日产av| 日本精品性网站在线观看| 亚洲第一男人av| 在线观看久久久久久| 国产精品久久久久久久久久久久久| 亚洲欧美精品中文字幕在线| 亚洲精品视频网上网址在线观看| 亚洲天堂精品在线| 欧美日韩成人在线视频| 日韩精品在线观| 亚洲精品中文字幕有码专区| 91亚洲午夜在线| 久久99久久99精品免观看粉嫩| 国内精品久久久久久久久| 羞羞色国产精品| 在线播放国产一区二区三区| www.日韩视频| 91美女高潮出水| 97国产精品免费视频| 国产婷婷色综合av蜜臀av| 色婷婷综合久久久久中文字幕1| 91亚洲午夜在线| 欧美韩日一区二区| 亚洲第一精品福利| 亚洲电影免费观看高清| 成人写真视频福利网| 久久久天堂国产精品女人| 亚洲成人激情视频| 伊人伊成久久人综合网小说| 97免费视频在线| 国产亚洲一区精品| 欧美激情中文字幕在线| 色噜噜狠狠狠综合曰曰曰88av| 中文.日本.精品| 精品国产一区二区三区久久狼5月| 91久久久久久久久久| 成人激情视频免费在线| 精品成人在线视频| 亚洲欧美日本精品| 欧美国产高跟鞋裸体秀xxxhd| 久久久久久久97| 91国内揄拍国内精品对白| 亚洲跨种族黑人xxx| 久久的精品视频| 国产福利成人在线| 精品国产一区二区三区四区在线观看| 一区二区成人av| 一区二区三区国产视频| 国产mv免费观看入口亚洲| 96pao国产成视频永久免费| 亚洲护士老师的毛茸茸最新章节| 欧美精品久久久久| 国产三级精品网站| 欧美一级大片在线观看| 91精品国产色综合久久不卡98| 欧美性xxxx极品hd满灌| 亚洲精品www久久久久久广东| 1769国内精品视频在线播放| 成人av番号网| 中文字幕日本精品| 精品一区二区三区电影| 欧美大片va欧美在线播放| 中文字幕久久亚洲| 亚洲乱码av中文一区二区| 亚洲国产欧美日韩精品| 久热国产精品视频| 日韩激情第一页| 久久久久久久一区二区三区| 久久国产精品久久久久| 国产精品第七十二页| 欧美日韩在线免费观看| 欧美高清视频一区二区| 亚洲春色另类小说| 日韩亚洲欧美中文在线| 亚洲精品久久久久久久久| 欧美视频精品一区| 国产亚洲成av人片在线观看桃| 国产精品视频yy9099| 日韩精品亚洲视频| 韩国三级电影久久久久久| 日韩精品高清在线观看| 日韩福利在线播放| 欧美电影免费观看高清完整| 欧美色xxxx| 亚洲在线免费观看| 日本精品性网站在线观看| 亚洲一级免费视频| 国产精品久久久久免费a∨大胸| 久久成人亚洲精品| 欧美激情综合亚洲一二区| 国内精品久久久久伊人av| 97精品一区二区视频在线观看| 久久久久久久国产| 久久人人爽亚洲精品天堂| 伊人久久久久久久久久久久久| 久久视频中文字幕| 亚洲成人a级网| 国产亚洲精品久久久优势| 性亚洲最疯狂xxxx高清| 国产精品一区二区三区久久| 国内精品小视频在线观看| 97国产真实伦对白精彩视频8| 成人高清视频观看www| 国产日韩在线亚洲字幕中文| 91久久国产综合久久91精品网站| 91av在线播放| 国产精品h在线观看| 在线丨暗呦小u女国产精品| 亚洲2020天天堂在线观看| 亚洲综合社区网| 91大神福利视频在线| 亚洲国产天堂网精品网站| 精品动漫一区二区三区| 在线看福利67194| 热草久综合在线| 欧美激情精品久久久久久黑人| 欧美丝袜美女中出在线| 亚洲欧美日韩国产中文| 91香蕉亚洲精品| 51久久精品夜色国产麻豆| 久久99国产综合精品女同| 亚洲第一精品夜夜躁人人爽| 亚洲色图欧美制服丝袜另类第一页| 欧美激情亚洲国产| 国产日韩在线亚洲字幕中文| 日韩av影片在线观看| 欧美日韩aaaa| 亚洲天堂av在线免费观看| 国产欧美日韩高清| 精品成人国产在线观看男人呻吟| 亚洲男女自偷自拍图片另类| 久久99精品视频一区97| 中文字幕久久久av一区| 亚洲欧美国产制服动漫| 午夜精品久久久久久久久久久久| 国产精品自拍网| 亚洲开心激情网| 欧美精品18videos性欧| 欧美高跟鞋交xxxxxhd| 国产精品免费视频久久久| 亚洲天堂男人的天堂|