down00112 2019-04-08 03:22
浏览 169

验证公共CA颁发的客户端证书

I have a question regarding x509 verify function

according to this example, https://golang.org/src/crypto/x509/example_test.go

    const rootPEM = `-----BEGIN CERTIFICATE-----
                     too long... skipped
                     -----END CERTIFICATE-----`

    const certPEM = `-----BEGIN CERTIFICATE-----
                     too long... skipped
                     -----END CERTIFICATE-----`

    roots := x509.NewCertPool()
    ok := roots.AppendCertsFromPEM([]byte(rootPEM))
    if !ok {
        panic("failed to parse root certificate")
    }

    block, _ := pem.Decode([]byte(certPEM))
    if block == nil {
        panic("failed to parse certificate PEM")
    }
    cert, err := x509.ParseCertificate(block.Bytes)
    if err != nil {
        panic("failed to parse certificate: " + err.Error())
    }

    opts := x509.VerifyOptions{
        DNSName: "mail.google.com",
        Roots:   roots,
    }

    if _, err := cert.Verify(opts); err != nil {
        panic("failed to verify certificate: " + err.Error())
    }

we can verify a client certificate using the root cert from the CA who has signed it. But I'm assuming this example is using a self-signed cert since it need to provide the root cert that I generated in order to recognize the certificate.

But what if the client certificate is signed by a public certificate authority like Godaddy or Symantec?

Do I still need to provide the root cert into the NewCertPool in advance? or this library will act like the browser, which already installed the root cert in the beginning and you don't have to import or do anything. If not, then can I import all the root cert from public CA at once? or I have to import them one by one manually?

Thank you so much for the patience reading my questions, any answers or suggestions are much appreciated!

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥15 请教:如何用postman调用本地虚拟机区块链接上的合约?
    • ¥15 为什么使用javacv转封装rtsp为rtmp时出现如下问题:[h264 @ 000000004faf7500]no frame?
    • ¥15 乘性高斯噪声在深度学习网络中的应用
    • ¥15 运筹学排序问题中的在线排序
    • ¥15 关于docker部署flink集成hadoop的yarn,请教个问题 flink启动yarn-session.sh连不上hadoop,这个整了好几天一直不行,求帮忙看一下怎么解决
    • ¥15 深度学习根据CNN网络模型,搭建BP模型并训练MNIST数据集
    • ¥15 C++ 头文件/宏冲突问题解决
    • ¥15 用comsol模拟大气湍流通过底部加热(温度不同)的腔体
    • ¥50 安卓adb backup备份子用户应用数据失败
    • ¥20 有人能用聚类分析帮我分析一下文本内容嘛