Programmatically Create X509 Certificate using OpenSSL

后端 未结 4 508
暖寄归人
暖寄归人 2020-11-27 10:25

I have a C/C++ application and I need to create a X509 pem certificate containing both a public and private key. The certificate can be self signed, or unsigned, doesn\'t m

4条回答
  •  佛祖请我去吃肉
    2020-11-27 10:39

    You'll need to familiarize yourself with the terminology and mechanisms first.

    An X.509 certificate, by definition, does not include a private key. Instead, it is a CA-signed version of the public key (along with any attributes the CA puts into the signature). The PEM format really only supports separate storage of the key and the certificate - although you can then concatenate the two.

    In any case, you'll need to invoke 20+ different functions of the OpenSSL API to create a key and a self-signed certificate. An example is in the OpenSSL source itself, in demos/x509/mkcert.c

    For a more detailed answer, please see Nathan Osman's explanation below.

提交回复
热议问题