1 回答

TA貢獻(xiàn)1775條經(jīng)驗(yàn) 獲得超8個(gè)贊
您可以使用類似 的庫(kù)google/certtostore
,它是一個(gè)多平臺(tái)包,允許您在 Linux 上使用 x509 證書,在 Windows 上使用證書存儲(chǔ)。
它不直接獲取證書包,而是使用WindowscertGetCertificateChain
調(diào)用,該調(diào)用從最終證書開(kāi)始構(gòu)建證書鏈上下文,并在可能的情況下返回到受信任的根 CA。
它由 所使用CertWithContext()
,它使用創(chuàng)建時(shí)提供的頒發(fā)者值執(zhí)行證書查找WinCertStore
。
它返回證書及其 Windows 上下文,可用于執(zhí)行其他操作,例如使用 查找私鑰CertKey()
。
無(wú)效的內(nèi)存地址或 nil 指針取消引用
你需要初始化var cert certmgr
更一般地說(shuō),您需要先獲取商店,如本例所示:
fmt.Println("open cert store")
// Open the local cert store. Provider generally shouldn't matter, so use Software which is ubiquitous. See comments in getHostKey.
store, err := certtostore.OpenWinCertStore(certtostore.ProviderMSSoftware, "", []string{"localhost"}, nil, false)
if err != nil {
fmt.Errorf("OpenWinCertStore: %v", err)
return
}
fmt.Println("get cert from cert store")
// Obtain the first cert matching all of container/issuers/intermediates in the store.
// This function is indifferent to the provider the store was opened with, as the store lists certs
// from all providers.
crt, context, err := store.CertWithContext()
if err != nil {
fmt.Println("failed to get cert from cert store. ", err)
return
}
if crt == nil {
fmt.Println("no cert")
return
}
fmt.Println("get key from cert")
// Obtain the private key from the cert. This *should* work regardless of provider because
// the key is directly linked to the certificate.
key, err := store.CertKey(context)
if err != nil {
fmt.Printf("private key not found in %s, %s", store.ProvName, err)
return
}
if key == nil {
fmt.Println("no key")
return
}
fmt.Printf("find cert '%s' with private key in container '%s', algo '%s'\n", crt.Subject, key.Container, key.AlgorithmGroup)
- 1 回答
- 0 關(guān)注
- 268 瀏覽
添加回答
舉報(bào)