【CFCA】CFCA根证书的查看和导入
用 openssl s_client 导出 www.cfca.com.cn 根证书、中间证书、服务器证书:
$ echo | openssl s_client -showcerts -connect www.cfca.com.cn:443 2> /dev/null | sed -n '/-----BEGIN CERTIFICATE-----/,/-----END CERTIFICATE-----/p' > www.cfca.com.cn.crt
导出的 www.cfca.com.cn.crt 文件 ,分为3部分,从上到下分别为 3部分:
中间机构给服务器颁发证书
Issuer: C=CN, O=China Financial Certification Authority, CN=CFCA EV OCA
Subject: CN=www.cfca.com.cn
CA:FALSE
根证书给中间机构颁发证书
Issuer: C=CN, O=China Financial Certification Authority, CN=CFCA EV ROOT
Subject: C=CN, O=China Financial Certification Authority, CN=CFCA OV OCA
CA:TRUE
根证书给自己颁发证书
Issuer: C=CN, O=China Financial Certification Authority, CN=CFCA EV ROOT
Subject: C=CN, O=China Financial Certification Authority, CN=CFCA EV ROOT
CA:TRUE
CFCA OV OCA和CFCA EV ROOT在验证级别和安全性上有所不同:
验证级别:CFCA OV OCA是组织验证(Organization Validation)类型的证书,其验证级别相对较低,只需要验证申请证书的组织是合法存在的。而CFCA EV ROOT则是扩展验证(Extended Validation)类型的证书,其验证级别更高,需要验证组织的合法存在性、经营情况、所有权等更多信息。
安全性:由于CFCA EV ROOT证书的验证级别更高,因此其安全性也相对更高。使用EV证书的网站在浏览器地址栏会显示绿色的小锁和组织的名称,这可以更好地保护用户的隐私和安全。
$ cat www.cfca.com.cn.crt
-----BEGIN CERTIFICATE-----
MIIHaDCCBlCgAwIBAgIKJDuK8HTWD+NBpDANBgkqhkiG9w0BAQsFADBVMQswCQYD
VQQGEwJDTjEwMC4GA1UECgwnQ2hpbmEgRmluYW5jaWFsIENlcnRpZmljYXRpb24g
QXV0aG9yaXR5MRQwEgYDVQQDDAtDRkNBIEVWIE9DQTAeFw0yMzA2MjcwODE0MjRa
Fw0yNDA3MTkwOTA3MDZaMIIBXDETMBEGCysGAQQBgjc8AgEDEwJDTjEXMBUGCysG
AQQBgjc8AgECDAbljJfkuqwxFzAVBgsrBgEEAYI3PAIBAQwG5YyX5LqsMR0wGwYD
VQQPDBRQcml2YXRlIE9yZ2FuaXphdGlvbjEbMBkGA1UEBRMSOTExMTAwMDA3NTk2
MjYwMjVVMQswCQYDVQQGEwJDTjEPMA0GA1UECAwG5YyX5LqsMQ8wDQYDVQQHDAbl
jJfkuqwxDzANBgNVBBEMBjEwMDAzNTFOMEwGA1UECQxF5YyX5Lqs5biC6KW/5Z+O
5Yy66I+c5biC5Y+j5Y2X5aSn6KGX5bmz5Y6f6YeMMjDlj7fmpbwxLTfjgIExLTnj
gIExLTEwMS0wKwYDVQQKDCTkuK3ph5Hph5Hono3orqTor4HkuK3lv4PmnInpmZDl
hazlj7gxGDAWBgNVBAMMD3d3dy5jZmNhLmNvbS5jbjCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBAKjkV210IoURdVKZGrOdIBlKB165AuccLEecFuj8jSdq
F5o8mmGOUiKDbj40pNfc/3jTugM3xPbzjOgeQlC/uq7WZnCKmCIJwbU7PZciD5tT
KzAdssRbAHfvqALgta2rtL1RMo2JxR7P+8V0szMdZ9SdEeA3uEfy47kaYnuE0Cuz
AGKw2I0hOXHfXW5q89jA6uWP9NxGD/CCSv9YwvMnDECnNSt5DJPcDPlpYmsOAzOd
fxLnMeui0OkWSbSNZMDwyU0NYldbJ98V0NWSbKfvkDoFaWkAhlBf8QErcmlNxgfQ
W5T5kSBtFXFsMfVpSJnrny8IkG9yTmiFI33anc15uJUCAwEAAaOCAy8wggMrMAkG
A1UdEwQCMAAwbAYIKwYBBQUHAQEEYDBeMCgGCCsGAQUFBzABhhxodHRwOi8vb2Nz
cC5jZmNhLmNvbS5jbi9vY3NwMDIGCCsGAQUFBzAChiZodHRwOi8vZ3RjLmNmY2Eu
Y29tLmNuL2V2b2NhL2V2b2NhLmNlcjA6BgNVHREEMzAxgg93d3cuY2ZjYS5jb20u
Y26CDW0uY2ZjYS5jb20uY26CD3NzbC5jZmNhLmNvbS5jbjAOBgNVHQ8BAf8EBAMC
BaAwHQYDVR0OBBYEFH4zuzX8pR3RBYo30EMdhLvxciCxMBMGA1UdJQQMMAoGCCsG
AQUFBwMBMIIBfQYKKwYBBAHWeQIEAgSCAW0EggFpAWcAdgDuzdBk1dsazsVct520
zROiModGfLzs3sNRSFlGcR+1mwAAAYj76xJ2AAAEAwBHMEUCIQCNDw+n2/rexdKa
4q0kHk5OyC1Hqz/S9NtCg+pCaZB9FgIgbHbZRwvBZMqPcECf9wkgKvVOlQY1vahI
W5rs9OgipvcAdQB2/4g/Crb7lVHCYcz1h7o0tKTNuyncaEIKn+ZnTFo6dAAAAYj7
6x6NAAAEAwBGMEQCIEQB7AiGxDaY+RTRje+S+L5OtVp1LRyUHtDV2kIYWMvxAiBC
0LoivIispCG8eWlbCt/edBWIqt+hXP7Q6rDV1YbZuQB2AEiw42vapkc0D+VqAvqd
MOscUgHLVt0sgdm7v6s52IRzAAABiPvrKX0AAAQDAEcwRQIgNZjxlg3Uu8qPgvBG
hxGq2NYN0Ix9dhUPX5+L8qWxZOoCIQD31Jdk79HpUebhKudtew36WpdEzdLcHIxi
ME5cK3cYFTAfBgNVHSMEGDAWgBRVCOLczJVtH13es0fo6RbGwEV3xDBQBgNVHSAE
STBHMDwGB2CBHIbvKgMwMTAvBggrBgEFBQcCARYjaHR0cDovL3d3dy5jZmNhLmNv
bS5jbi91cy91cy0xMi5odG0wBwYFZ4EMAQEwPAYDVR0fBDUwMzAxoC+gLYYraHR0
cDovL2NybC5jZmNhLmNvbS5jbi9ldm9jYS9SU0EvY3JsMjAzLmNybDANBgkqhkiG
9w0BAQsFAAOCAQEAYBWOt1XXIE5oOI5iwF8sq4glQmnTsx0bYkaUvlx44fmqhUAC
JDM7ygfdqfDd+7C2nipFMTq5Xw/p4kpVPf6x/APopL7hBAw9SGamTEs645Ip2pn+
CSkyo6IU8thL8ztzpYChOxQOulnK0XY0ft8huoQ8qFLcoCAF7pLTW1MtyiUAim/0
nI24O57+SQkgP/q5KEjxE+t3WOud3YnQ70zfWyk4xOmESSp2mvKEjcJxZSbiGhNL
BNpqguZDZK9nEhuEN0UsLQ1ewGB+P+1GNNSCTJi69+p6EnAe+91TYXGlJn79DOWW
OlOk5xCVw9RXmqOqGC2MDfzS8gT0ZsPmPBFIBA==
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFTjCCAzagAwIBAgIGALTPlDJmMA0GCSqGSIb3DQEBCwUAMFYxCzAJBgNVBAYT
AkNOMTAwLgYDVQQKDCdDaGluYSBGaW5hbmNpYWwgQ2VydGlmaWNhdGlvbiBBdXRo
b3JpdHkxFTATBgNVBAMMDENGQ0EgRVYgUk9PVDAeFw0xMjA4MDgwNjA2MzFaFw0y
OTEyMjkwNjA2MzFaMFUxCzAJBgNVBAYTAkNOMTAwLgYDVQQKDCdDaGluYSBGaW5h
bmNpYWwgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxFDASBgNVBAMMC0NGQ0EgRVYg
T0NBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA02OMsGFxFQIPMKVP
oRaO9rHNX41xbq8jhnbdK0MDVbxfGa3b8QTKxMcmxlRlULfsaie0cIlaRl0AUcJP
QH9ftekzh4T287xqsEAydYQHf77arWQ5nY3fR9RcoBq9pTCQbqw49S6/jHA5oPQa
EoKbF0G8zfVKp5PrcKSufHMQyKo/Ez2UYT+gut36j4GYpAABuV6PbusPpjufsN9B
r9+xqgyz8ubSp1Wl1qSlvQUQBhAJAH+a3NMhD0illaGfTdWbF485a5NilMFGqJBa
/kLVEYwG4aoKdV9vG/NFS0LKz3QVnB7bkrLjTkuGN/zQJP0daJ3CGAzmN+Cr2ujt
XOfAYwIDAQABo4IBITCCAR0wOAYIKwYBBQUHAQEELDAqMCgGCCsGAQUFBzABhhxo
dHRwOi8vb2NzcC5jZmNhLmNvbS5jbi9vY3NwMB8GA1UdIwQYMBaAFOP+Lf0o0Au1
uraixL8GqgWMk/svMA8GA1UdEwEB/wQFMAMBAf8wRAYDVR0gBD0wOzA5BgRVHSAA
MDEwLwYIKwYBBQUHAgEWI2h0dHA6Ly93d3cuY2ZjYS5jb20uY24vdXMvdXMtMTIu
aHRtMDoGA1UdHwQzMDEwL6AtoCuGKWh0dHA6Ly9jcmwuY2ZjYS5jb20uY24vZXZy
Y2EvUlNBL2NybDEuY3JsMA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUVQji3MyV
bR9d3rNH6OkWxsBFd8QwDQYJKoZIhvcNAQELBQADggIBAMmFEIoCE9UNmb2BYYhT
RV12kNVucP6t683BaFTgJizIJw/ebvvTdWNTycyP5MQFlHKrIYwjvFO9Rfw8+yIs
sT3JFYiqsLBswvaMr3AIuA2mTnmasvZFe6P19qitzTRkz+TL6TFailrtnzudsvn2
SeVbRiX+6CsyNNMoPsRHTeZAEpkB7J3vh+ZAiv3gsIXtjtz5Y1iWWRZipemJ/qEf
W2hDONB+T6lGcEXHDi9dIkWcC/jFT4XPM64pagAz9gEGZg1PzFBE8QMxiwaDAOea
G0l0e/HW4wJlo4ZzOELqZGJLlYhQ8AkBYR95NEtR9j5bWK98Lznykldk2MDLBD2m
rIfMkVjMwEj4A8ElMXsLnWXXg41NN6gjUm2/IudKOaGqniPs5SZrN36O4B3NzsaZ
dLznHH5H0+aksurjgme8RAG0A2OAnRG3VXBWrxud7t0KDINLs+mxY7IR+xVZ2cw6
Cer8HnAVfKPJrbdq7vyJJkIpCll+mLHaGgvv3IqiU4rrrllE3NYjKG4Fk2MiYvZg
10KXA8tlYsLt8I/RcNmC2TvjZHYVE3tanbGw53TRGFk2Vq68XOkvooOardihwRkg
qcOgUvouORuvSqTlkQizTFH6FTUt3xuuED4dnn5N/1ijcDt0N3l5ovoyHOVcYiO4
drCN96LHiUoiSfYODmpXG2tl
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFjTCCA3WgAwIBAgIEGErM1jANBgkqhkiG9w0BAQsFADBWMQswCQYDVQQGEwJD
TjEwMC4GA1UECgwnQ2hpbmEgRmluYW5jaWFsIENlcnRpZmljYXRpb24gQXV0aG9y
aXR5MRUwEwYDVQQDDAxDRkNBIEVWIFJPT1QwHhcNMTIwODA4MDMwNzAxWhcNMjkx
MjMxMDMwNzAxWjBWMQswCQYDVQQGEwJDTjEwMC4GA1UECgwnQ2hpbmEgRmluYW5j
aWFsIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MRUwEwYDVQQDDAxDRkNBIEVWIFJP
T1QwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDXXWvNED8fBVnVBU03
sQ7smCuOFR36k0sXgiFxEFLXUWRwFsJVaU2OFW2fvwwbwuCjZ9YMrM8irq93VCpL
TIpTUnrD7i7es3ElweldPe6hL6P3KjzJIx1qqx2hp/Hz7KDVRM8Vz3IvHWOX6Jn5
/ZOkVIBMUtRSqy5J35DNuF++P96hyk0g1CXohClTt7GIH//62pCfCqktQT+x8Rgp
7hZZLDRJGqgG16iI0gNyejLi6mhNbiyWZXvKWfry4t3uMCz7zEasxGPrb382KzRz
EpR/38wmnvFyXVBlWY9ps4deMm/DGIq1lY+wejfeWkU7xzbh72fROdOXW3NiGUgt
hxwG+3SYIElz8AXSG7Ggo7cbcNOIabla1jj0Ytwli3i/+Oh+uFzJlU9fpy25IGvP
a931DfSCt/SyZi4QKPaXWnuWFo8BGS1sbn85WAZkgwGDg8NNkt0yxoekN+kWzqot
aK8KgWU6cMGbrU1tVMoqLUuFG7OA5nBFDWteNfB/O7ic5ARwiRIlk9oKmSJgamNg
TnYGmE69g60dWIolhdLHZR4tjsbftsbhf4oEIRUpdPA+nJCdDC7xij5aqgwJHsfV
PKPtl8MeNPo4+QgO48BdK4PRVmrJtqhUUy54Mmc9gn900PvhtgVguXDbjgv5E1hv
cWAQUhC5wUEJ73IfZzF4/5YFjQIDAQABo2MwYTAfBgNVHSMEGDAWgBTj/i39KNAL
tbq2osS/BqoFjJP7LzAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAd
BgNVHQ4EFgQU4/4t/SjQC7W6tqLEvwaqBYyT+y8wDQYJKoZIhvcNAQELBQADggIB
ACXGumvrh8vegjmWPfBEp2uEcwPenStPuiB/vHiyz5ewG5zz13ku9Ui20vsXiObT
ej/tUxPQ4i9qecsAIyjmHjdXNYmEwnZPNDatZ8POQQaIxffu2Bq41gt/UP+TqhdL
jOztUmCypAbqTuv0axn96/Ua4CUqmtzHQTb3yHQFhDmVOdYLO6Qn+gjYXB74BGBS
ESgoA//vU2YApUo0FmZ8/Qmkrp5nGm9BC2sGE5uPhnEFtC+NiWYzKXZUmhH4J/qy
P5Hgzg0b8zAarb8iXRvTvyUFTeGSGn+ZnzxEk8rUQElsgIfXBDrDMlI1Dlb4pd19
xIsNER9Tyx6yF7Zod1rg1MvIB671Oi6ON7fQAUtDKXeMOZePglr4UeWJoBjnaH9d
Ci77o0cOPaYjesYBx4/IXr9tgFa+iiS6M+qf4TIRnvHST4D2G0CvOJ4RUHlzEhLN
5mydLIhyPDCBBpEi6lmt2hkuIsKNuYyH4Ga8cyNfIWRjgEj1oDwYPZTISEEdQLpe
/v5WOaHIz16eGWRGENoXkbcFgKyLmZJ956LYBws2J+dIeWCKw9cTXPhyQN9Ky8+Z
AAoACxGV2lZFA4gKn2fQ1XmxqI1AbQ3CekD6819kR5LLU7m7Wc5P/dAVUwHY3+vZ
5nbv0CO7O6l5s9UCKc2Jo5YPSjXnTkLAdc0Hz+Ys63su
-----END CERTIFICATE-----
从上到下
openssl x509 只看了证书的第一部分
$ openssl x509 -noout -text -in www.cfca.com.cn
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
24:3b:8a:f0:74:d6:0f:e3:41:a4
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=CN, O=China Financial Certification Authority, CN=CFCA EV OCA
Validity
Not Before: Jun 27 08:14:24 2023 GMT
Not After : Jul 19 09:07:06 2024 GMT
Subject: jurisdictionC=CN/jurisdictionST=\xE5\x8C\x97\xE4\xBA\xAC/jurisdictionL=\xE5\x8C\x97\xE4\xBA\xAC/businessCategory=Private Organization/serialNumber=91110000759626025U, C=CN, ST=\xE5\x8C\x97\xE4\xBA\xAC, L=\xE5\x8C\x97\xE4\xBA\xAC/postalCode=100035/street=\xE5\x8C\x97\xE4\xBA\xAC\xE5\xB8\x82\xE8\xA5\xBF\xE5\x9F\x8E\xE5\x8C\xBA\xE8\x8F\x9C\xE5\xB8\x82\xE5\x8F\xA3\xE5\x8D\x97\xE5\xA4\xA7\xE8\xA1\x97\xE5\xB9\xB3\xE5\x8E\x9F\xE9\x87\x8C20\xE5\x8F\xB7\xE6\xA5\xBC1-7\xE3\x80\x811-9\xE3\x80\x811-10, O=\xE4\xB8\xAD\xE9\x87\x91\xE9\x87\x91\xE8\x9E\x8D\xE8\xAE\xA4\xE8\xAF\x81\xE4\xB8\xAD\xE5\xBF\x83\xE6\x9C\x89\xE9\x99\x90\xE5\x85\xAC\xE5\x8F\xB8, CN=www.cfca.com.cn
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:a8:e4:57:6d:74:22:85:11:75:52:99:1a:b3:9d:
20:19:4a:07:5e:b9:02:e7:1c:2c:47:9c:16:e8:fc:
8d:27:6a:17:9a:3c:9a:61:8e:52:22:83:6e:3e:34:
a4:d7:dc:ff:78:d3:ba:03:37:c4:f6:f3:8c:e8:1e:
42:50:bf:ba:ae:d6:66:70:8a:98:22:09:c1:b5:3b:
3d:97:22:0f:9b:53:2b:30:1d:b2:c4:5b:00:77:ef:
a8:02:e0:b5:ad:ab:b4:bd:51:32:8d:89:c5:1e:cf:
fb:c5:74:b3:33:1d:67:d4:9d:11:e0:37:b8:47:f2:
e3:b9:1a:62:7b:84:d0:2b:b3:00:62:b0:d8:8d:21:
39:71:df:5d:6e:6a:f3:d8:c0:ea:e5:8f:f4:dc:46:
0f:f0:82:4a:ff:58:c2:f3:27:0c:40:a7:35:2b:79:
0c:93:dc:0c:f9:69:62:6b:0e:03:33:9d:7f:12:e7:
31:eb:a2:d0:e9:16:49:b4:8d:64:c0:f0:c9:4d:0d:
62:57:5b:27:df:15:d0:d5:92:6c:a7:ef:90:3a:05:
69:69:00:86:50:5f:f1:01:2b:72:69:4d:c6:07:d0:
5b:94:f9:91:20:6d:15:71:6c:31:f5:69:48:99:eb:
9f:2f:08:90:6f:72:4e:68:85:23:7d:da:9d:cd:79:
b8:95
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints:
CA:FALSE
Authority Information Access:
OCSP - URI:http://ocsp.cfca.com.cn/ocsp
CA Issuers - URI:http://gtc.cfca.com.cn/evoca/evoca.cer
X509v3 Subject Alternative Name:
DNS:www.cfca.com.cn, DNS:m.cfca.com.cn, DNS:ssl.cfca.com.cn
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Subject Key Identifier:
7E:33:BB:35:FC:A5:1D:D1:05:8A:37:D0:43:1D:84:BB:F1:72:20:B1
X509v3 Extended Key Usage:
TLS Web Server Authentication
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1(0)
Log ID : EE:CD:D0:64:D5:DB:1A:CE:C5:5C:B7:9D:B4:CD:13:A2:
32:87:46:7C:BC:EC:DE:C3:51:48:59:46:71:1F:B5:9B
Timestamp : Jun 27 08:14:26.934 2023 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:21:00:8D:0F:0F:A7:DB:FA:DE:C5:D2:9A:E2:
AD:24:1E:4E:4E:C8:2D:47:AB:3F:D2:F4:DB:42:83:EA:
42:69:90:7D:16:02:20:6C:76:D9:47:0B:C1:64:CA:8F:
70:40:9F:F7:09:20:2A:F5:4E:95:06:35:BD:A8:48:5B:
9A:EC:F4:E8:22:A6:F7
Signed Certificate Timestamp:
Version : v1(0)
Log ID : 76:FF:88:3F:0A:B6:FB:95:51:C2:61:CC:F5:87:BA:34:
B4:A4:CD:BB:29:DC:68:42:0A:9F:E6:67:4C:5A:3A:74
Timestamp : Jun 27 08:14:30.029 2023 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:44:01:EC:08:86:C4:36:98:F9:14:D1:8D:
EF:92:F8:BE:4E:B5:5A:75:2D:1C:94:1E:D0:D5:DA:42:
18:58:CB:F1:02:20:42:D0:BA:22:BC:88:AC:A4:21:BC:
79:69:5B:0A:DF:DE:74:15:88:AA:DF:A1:5C:FE:D0:EA:
B0:D5:D5:86:D9:B9
Signed Certificate Timestamp:
Version : v1(0)
Log ID : 48:B0:E3:6B:DA:A6:47:34:0F:E5:6A:02:FA:9D:30:EB:
1C:52:01:CB:56:DD:2C:81:D9:BB:BF:AB:39:D8:84:73
Timestamp : Jun 27 08:14:32.829 2023 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:20:35:98:F1:96:0D:D4:BB:CA:8F:82:F0:46:
87:11:AA:D8:D6:0D:D0:8C:7D:76:15:0F:5F:9F:8B:F2:
A5:B1:64:EA:02:21:00:F7:D4:97:64:EF:D1:E9:51:E6:
E1:2A:E7:6D:7B:0D:FA:5A:97:44:CD:D2:DC:1C:8C:62:
30:4E:5C:2B:77:18:15
X509v3 Authority Key Identifier:
keyid:55:08:E2:DC:CC:95:6D:1F:5D:DE:B3:47:E8:E9:16:C6:C0:45:77:C4
X509v3 Certificate Policies:
Policy: 2.16.156.112554.3
CPS: http://www.cfca.com.cn/us/us-12.htm
Policy: 2.23.140.1.1
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.cfca.com.cn/evoca/RSA/crl203.crl
Signature Algorithm: sha256WithRSAEncryption
60:15:8e:b7:55:d7:20:4e:68:38:8e:62:c0:5f:2c:ab:88:25:
42:69:d3:b3:1d:1b:62:46:94:be:5c:78:e1:f9:aa:85:40:02:
24:33:3b:ca:07:dd:a9:f0:dd:fb:b0:b6:9e:2a:45:31:3a:b9:
5f:0f:e9:e2:4a:55:3d:fe:b1:fc:03:e8:a4:be:e1:04:0c:3d:
48:66:a6:4c:4b:3a:e3:92:29:da:99:fe:09:29:32:a3:a2:14:
f2:d8:4b:f3:3b:73:a5:80:a1:3b:14:0e:ba:59:ca:d1:76:34:
7e:df:21:ba:84:3c:a8:52:dc:a0:20:05:ee:92:d3:5b:53:2d:
ca:25:00:8a:6f:f4:9c:8d:b8:3b:9e:fe:49:09:20:3f:fa:b9:
28:48:f1:13:eb:77:58:eb:9d:dd:89:d0:ef:4c:df:5b:29:38:
c4:e9:84:49:2a:76:9a:f2:84:8d:c2:71:65:26:e2:1a:13:4b:
04:da:6a:82:e6:43:64:af:67:12:1b:84:37:45:2c:2d:0d:5e:
c0:60:7e:3f:ed:46:34:d4:82:4c:98:ba:f7:ea:7a:12:70:1e:
fb:dd:53:61:71:a5:26:7e:fd:0c:e5:96:3a:53:a4:e7:10:95:
c3:d4:57:9a:a3:aa:18:2d:8c:0d:fc:d2:f2:04:f4:66:c3:e6:
3c:11:48:04
如果要用 keytool 命令将这些证书导入到证书库,需要拆成多段,一个个导入!!!
keytool将他签名证书导入到jre证书管理库
https://www.jianshu.com/p/04bb1b8c20bf
上一篇: 调用CFCA安心签相关接口,很详细
下一篇: CFCA证书是什么?是干嘛用的?
