首页 > 解决方案 > 如何使用 OpenSSL 验证证书

问题描述

这是我为测试证书是否对 OpenSSL 有效所做的:

# Combine

me@VSPACE MINGW64 ~/Downloads/STAR_mynewdomain_com
$ cat STAR_mynewdomain_com.crt comodorsadomainvalidationsecureserverca.crt comodorsaaddtrustca.crt  addtrustexternalcaroot.
crt > mynewdomain-ssl-bundle.crt

# Create PEM file

me@VSPACE MINGW64 ~/Downloads/STAR_mynewdomain_com
$ openssl x509 -inform PEM -in mynewdomain-ssl-bundle.crt > public.pem

# Validate Certificate

me@VSPACE MINGW64 ~/Downloads/STAR_mynewdomain_com
$ openssl verify public.pem
OU = Domain Control Validated, OU = PositiveSSL Wildcard, CN = *.mynewdomain.com
error 20 at 0 depth lookup: unable to get local issuer certificate
error public.pem: verification failed

不知道我错过了什么,但它不会说它是有效的,但如果我使用 Digicert Windows 实用程序检查证书 ( mynewdomain-ssl-bundle.crt) 证书是否有效。

标签: sslopenssl

解决方案


推荐阅读