drtzb06222 2017-08-30 21:32
浏览 526
已采纳

如何检查CA颁发的PEM证书的有效性

I have a certificate (PEM), and I'd like to check if the certificate is valid and signed by CA. I already have the CA certificate (PEM). What is a simple, but secure way to check the certificate in Go, using the standard crypto/x509 package?

  • 写回答

1条回答 默认 最新

  • dongnai5905 2017-08-30 22:13
    关注

    You need to use Certificate.Verify(). There is an example for exactly what you want to do in the docs:

    https://golang.org/pkg/crypto/x509/#example_Certificate_Verify

    func verifyCert(rootPEM, certPEM string, name string) error {
        roots := x509.NewCertPool()
        ok := roots.AppendCertsFromPEM([]byte(rootPEM))
        if !ok {
            return fmt.Errorf("failed to parse root certificate")
        }
    
        block, _ := pem.Decode([]byte(certPEM))
        if block == nil {
            return fmt.Errorf("failed to parse certificate PEM")
        }
        cert, err := x509.ParseCertificate(block.Bytes)
        if err != nil {
            return fmt.Errorf("failed to parse certificate: %v", err.Error())
        }
    
        opts := x509.VerifyOptions{
            DNSName: name,
            Roots:   roots,
        }
    
        if _, err := cert.Verify(opts); err != nil {
            return fmt.Errorf("failed to verify certificate: %v", err.Error())
        }
    
        return nil
    }
    

    DISCLAIMER: I reorganized it as a function and removed the panics for error handling. The code is otherwise unchanged from the example in the official documentation.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 删除虚拟显示器驱动 删除所有 Xorg 配置文件 删除显示器缓存文件 重启系统 可是依旧无法退出虚拟显示器
  • ¥15 vscode程序一直报同样的错,如何解决?
  • ¥15 关于使用unity中遇到的问题
  • ¥15 开放世界如何写线性关卡的用例(类似原神)
  • ¥15 关于并联谐振电磁感应加热
  • ¥60 请查询全国几个煤炭大省近十年的煤炭铁路及公路的货物周转量
  • ¥15 请帮我看看我这道c语言题到底漏了哪种情况吧!
  • ¥66 如何制作支付宝扫码跳转到发红包界面
  • ¥15 pnpm 下载element-plus
  • ¥15 解决编写PyDracula时遇到的问题