Redian新闻
>
请问一个在openssl编程中遇到的问题。
avatar
请问一个在openssl编程中遇到的问题。# Security - 系统安全
x*n
1
偶想用openssl的库做一个CA出来,可是在openssl的库函数说明
里面没有查到有关PKI Message的定义以及相应的操作,
我只能找到X509_REQ这样的证书请求处理函数,没有诸如证书失效
请求/应答函数,密钥失效请求/应答函数。
还请做过类似东东的大虾指教,小弟先谢过了。
avatar
m*t
2
Operation protocol should be LDAP ba? form the request using X509 PKCS format,
then use LDAP to req/reply with the X509 payload. only my understanding, could
be wrong.

【在 x*****n 的大作中提到】
: 偶想用openssl的库做一个CA出来,可是在openssl的库函数说明
: 里面没有查到有关PKI Message的定义以及相应的操作,
: 我只能找到X509_REQ这样的证书请求处理函数,没有诸如证书失效
: 请求/应答函数,密钥失效请求/应答函数。
: 还请做过类似东东的大虾指教,小弟先谢过了。

avatar
x*n
3
象你说的这样,这种消息机制遵循ldap协议的话,
偶在openssl中是 找不到此种处理函数了。
只能根据ldap的协议自己定义消息,自己做处理了,
看来很麻烦的说。

【在 m**t 的大作中提到】
: Operation protocol should be LDAP ba? form the request using X509 PKCS format,
: then use LDAP to req/reply with the X509 payload. only my understanding, could
: be wrong.

avatar
m*t
4
actually one way to do it is that get the source code of all the
CA and CRL comandline utilities and make it a lib for yourself.
thus you have all the utilities APIs to manage ur CA stuff, but
regarding the req revoke whatever operations between Client and CA, the
LDAP is also an open source.
If you don't like to do all these, get a toolkit
from leading PKI vendors like entrust, certicom OpenSSL is not the
way to go, the only useful stuff from there I foun dis the cryptolibrary
... good luck

【在 x*****n 的大作中提到】
: 象你说的这样,这种消息机制遵循ldap协议的话,
: 偶在openssl中是 找不到此种处理函数了。
: 只能根据ldap的协议自己定义消息,自己做处理了,
: 看来很麻烦的说。

avatar
m*t
5
by the way, LDAP is only one of the access protocol
well, check www.entrust.com/resourcecenter/pdf/standards.pdf

【在 m**t 的大作中提到】
: actually one way to do it is that get the source code of all the
: CA and CRL comandline utilities and make it a lib for yourself.
: thus you have all the utilities APIs to manage ur CA stuff, but
: regarding the req revoke whatever operations between Client and CA, the
: LDAP is also an open source.
: If you don't like to do all these, get a toolkit
: from leading PKI vendors like entrust, certicom OpenSSL is not the
: way to go, the only useful stuff from there I foun dis the cryptolibrary
: ... good luck

相关阅读
logo
联系我们隐私协议©2024 redian.news
Redian新闻
Redian.news刊载任何文章,不代表同意其说法或描述,仅为提供更多信息,也不构成任何建议。文章信息的合法性及真实性由其作者负责,与Redian.news及其运营公司无关。欢迎投稿,如发现稿件侵权,或作者不愿在本网发表文章,请版权拥有者通知本网处理。