gpt4 book ai didi

c# - .Net 使用 Bouncy CaSTLe 以编程方式签署 PKCS#10 请求

转载 作者:太空狗 更新时间:2023-10-29 22:27:47 25 4
gpt4 key购买 nike

我们使用 CertEnroll 在客户端上生成了一个有效的 PKCS#10 证书请求。

现在我们需要对其进行签名并将结果返回给客户端,CertEnroll 将在客户端处理本地证书存储。

这是一个 B2B 应用程序,根签名证书将自行生成,或者我们可以使用现有的 Thawte SSL 证书。

服务器 (2008) 没有运行 Active Directory,除非绝对必要,否则我们不想为此创建独立的签名基础架构/服务。不需要撤销等 - 我们希望以编程方式进行。

我很乐意使用 BouncyCaSTLe 库,但是 C# 库缺少任何有意义的文档,虽然原始 Java 文档公认相似,但 C# 实现的不同足以让我有点困惑。

是否有人知道(或拥有)示例 C#(或 VB)代码或已知可靠的相同链接,使用 BouncyCaSTLe 或就此而言使用 native .Net 类?

对于完成这件事的任何帮助,我们将不胜感激!

最佳答案

至少可以说这是一个有趣的练习:-)

我们同时使用了 BouncyCaSTLe 和 .Net 证书对象。解决方案仍然有 !much!有改进的余地,但它确实有效。

它的核心 (Cert Gen) 如下。当我们到达这里时,CSR 已经在客户端上生成,当我们离开时,生成的证书由客户端代码安装(请参阅 this blog 了解客户端工作。)

再次声明,我不是将其作为成品提供,而是希望对面临相同任务的人有一定的值(value)。快乐加密:-)

        // Jul 10, 2012 see
// http://social.technet.microsoft.com/Forums/en-NZ/winserversecurity/thread/45781b46-3eb7-4715-b877-883bf0dc2ae7
// instaed of CX509CertificateRequestPkcs10 csr = new CX509CertificateRequestPkcs10(); use:
IX509CertificateRequestPkcs10 csr = (IX509CertificateRequestPkcs10)Activator.CreateInstance(Type.GetTypeFromProgID("X509Enrollment.CX509CertificateRequestPkcs10"));
csr.InitializeDecode(csrText, EncodingType.XCN_CRYPT_STRING_BASE64);
csr.CheckSignature(Pkcs10AllowedSignatureTypes.AllowedKeySignature);

//get Bouncy CSRInfo Object
Trace.Write("get Bouncy CSRInfo Object");
Byte[] csrBytes = Convert.FromBase64String(csrText);
CertificationRequestInfo csrInfo = CertificateTools.GetCsrInfo(csrBytes);
SubjectPublicKeyInfo pki = csrInfo.SubjectPublicKeyInfo;

//pub key for the signed cert
Trace.Write("pub key for the signed cert");
AsymmetricKeyParameter publicKey = PublicKeyFactory.CreateKey(pki);

// Build a Version1 (No Extensions) Certificate
DateTime startDate = DateTime.Now;
DateTime expiryDate = startDate.AddYears(100);
BigInteger serialNumber = new BigInteger(32, new Random());

Trace.Write("Build a Version1 (No Extensions) Certificate");
X509V1CertificateGenerator certGen = new X509V1CertificateGenerator();
string signerCN = ConfigurationManager.AppSettings["signerCN"].ToString();
X509Name dnName = new X509Name(String.Format("CN={0}", signerCN));
X509Name cName = new X509Name(csr.Subject.Name);
certGen.SetSerialNumber(serialNumber);
certGen.SetIssuerDN(dnName);
certGen.SetNotBefore(startDate);
certGen.SetNotAfter(expiryDate);
certGen.SetSubjectDN(cName);
certGen.SetSignatureAlgorithm("SHA1withRSA");
certGen.SetPublicKey(publicKey);

//get our Private Key to Sign with
Trace.Write("get our Private Key to Sign with");
X509Store store = new X509Store(StoreLocation.LocalMachine);
store.Open(OpenFlags.ReadOnly);
string signerThumbprint = ConfigurationManager.AppSettings["signerThumbprint"].ToString();
X509Certificate2Collection collection = (X509Certificate2Collection)store.Certificates;
X509Certificate2Collection fcollection = (X509Certificate2Collection)collection.Find(X509FindType.FindByThumbprint, signerThumbprint, false);
X509Certificate2 caCert = fcollection[0];

Trace.Write("Found:" + caCert.FriendlyName);
Trace.Write("Has Private " + caCert.HasPrivateKey.ToString());
Trace.Write("Key Size " + caCert.PrivateKey.KeySize.ToString());

//Get our Signing Key as a Bouncy object
Trace.Write("Get our Signing Key as a Bouncy object from key ");
AsymmetricCipherKeyPair caPair = DotNetUtilities.GetKeyPair(caCert.PrivateKey);

//gen BouncyCastle object
Trace.Write("gen BouncyCastle object");
Org.BouncyCastle.X509.X509Certificate cert = certGen.Generate(caPair.Private);

//convert to windows type 2 and get Base64 String
Trace.Write("convert to windows type 2 and get Base64 String");
X509Certificate2 cert2 = new X509Certificate2(DotNetUtilities.ToX509Certificate(cert));
byte[] encoded = cert2.GetRawCertData();
string certOutString = Convert.ToBase64String(encoded);

//output to the page (hidden)
Certificate.Value = certOutString;

关于c# - .Net 使用 Bouncy CaSTLe 以编程方式签署 PKCS#10 请求,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/9592516/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com