根证书验证子签名:openssl verify -CAfile root.crt sub.crt
两种cer转crt:
openssl x509 -inform DER -in certificate.cer -out certificate.crt
openssl x509 -inform PEM -in certificate.cer -out certificate.crt
查看证书信息:
openssl x509 -text -noout -in ca.crt
验证两个证书是否匹配:
diff -eq <(openssl x509 -pubkey -noout -in ca.crt) <(openssl rsa -pubout -in ca.key)
转换证书格式:
1)DER 转换为 PEM
运行以下命令进行证书转化:
openssl x509 -inform der -in certificate.cer -out certificate.pem
运行以下命令进行私钥转化:
openssl rsa -inform DER -outform PEM -in privatekey.der -out privatekey.pem
2)P7B 转换为 PEM
运行以下命令进行证书转化:
openssl pkcs7 -print_certs -in incertificat.p7b -out outcertificate.cer
3)PFX 转换为PEM
运行以下命令提取私钥:
openssl pkcs12 -in certname.pfx -nocerts -out key.pem -nodes
运行以下命令提取证书:
openssl pkcs12 -in certname.pfx -nokeys -out cert.pem
网友评论