9

我生成RSA了密钥,我的后端在BASE64(signatureAlgorithm 除外)中发送了 3 个参数来创建CSR给我:

"subject" : "MIGfMQswCQYDVQQGEwJJUjEvMC0GA1UEAwwmMTAwMDAwMzg1MDA3NjAxMy3YqNmH2LLYp9ivINi12KfYr9mC24wxGTAXBgNVBAUTEDEwMDAwMDM4NTAwNzYwMTMxEzARBgNVBCoMCtio2YfYstin2K8xEzARBgNVBAQMCti12KfYr9mC24wxGjAYBgkqhkiG9w0BCQEWC2luZm9AdWlkLmly",
"extensions" : "MDMwDgYDVR0PAQH/BAQDAgXgMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMCMAkGA1UdEQQCMAA="
"signatureAlgorithm" : "SHA256_WITH_RSA"

我在 Android/java 中BouncyCastle有用于执行此操作的示例代码:

byte[] subjectBytes = EncodingUtils.decode(receivedSubject);
byte[] extensionsBytes = EncodingUtils.decode(receivedExtensions);

X500Name subject = X500Name.getInstance(ASN1Primitive.fromByteArray(subjectBytes));
Extensions extensions = Extensions.getInstance(ASN1Primitive.fromByteArray(extensionsBytes));

PKCS10CertificationRequestBuilder p10Builder = new JcaPKCS10CertificationRequestBuilder(subject, publicKey);

if (extensions != null)
    p10Builder.addAttribute(PKCSObjectIdentifiers.pkcs_9_at_extensionRequest, extensions);

ContentSigner signer = new ContentSigner() {

    final ByteArrayOutputStream outputStream = new ByteArrayOutputStream();

    @Override
    public AlgorithmIdentifier getAlgorithmIdentifier() {
        return new DefaultSignatureAlgorithmIdentifierFinder()
                .find(receivedAlgorithm);
    }

    @Override
    public OutputStream getOutputStream() {
        return this.outputStream;
    }

    @Override
    public byte[] getSignature() {
        try {
            byte[] tbs = ((ByteArrayOutputStream) getOutputStream()).toByteArray();

            return SignatureHelper.sign(privateKey, tbs,
                    csrFormat.getSignatureProfile().getSignatureAlgorithm());
        } catch (NoSuchAlgorithmException | InvalidKeyException | SignatureException e) {
            throw new CsrGenerationException();
        }
    }
};

return p10Builder.build(signer).getEncoded();

如何在 iOS 中使用 swift 做同样的事情?

是否有任何图书馆可以接受subjectextensions创建 CSR 并签名?

4

0 回答 0