zxm256 / Nginx-with-GmSSLv3

An modified Nginx with GmSSL
125 stars 37 forks source link

reqsign_ext.sh脚本有问题 #5

Closed SmartisanR1 closed 1 year ago

SmartisanR1 commented 2 years ago

gmssl 3.0更改了命令行模式,和openssl以及之前的区分开,但是命令还有问题,具体如下: 执行该生成证书脚本,有如下错误提示:

certgen: '-key_usage' option required
reqsign: parse CA certificate failure

经查看,生成的证书内容都是空的,问题出在根证书生成失败,需要一个 “密钥用途的关键字”。 手动加上关键字后:

gmssl certgen -C CN -ST Beijing -L Haidian -O PKU -OU CS -CN CA -days 365 -key cakey.pem -pass 123456 -out cacert.pem -key_usage digitalSignature

报错:

/home/GmSSL-develop/src/asn1.c:458:asn1_integer_to_der_ex():
/home/GmSSL-develop/src/x509_ext.c:671:x509_authority_key_identifier_to_der():
/home/GmSSL-develop/src/x509_ext.c:113:x509_exts_add_authority_key_identifier():
/home/GmSSL-develop/src/x509_ext.c:131:x509_exts_add_default_authority_key_identifier():
certgen: inner error

希望您解决一下,生成证书需要传入什么参数呢,还是说是由于关老师的GMSSL有问题

zxm256 commented 2 years ago

目前已经更新,如果有问题请与我沟通

github-actions[bot] commented 1 year ago

Marked as stale issue. Will be closed later if no activity for a while.