アットウィキロゴ
  • 「標準から逸脱」したのとはちょっと違うかもしれないですが、GCC (GNU Compiler Collection) 4.3.2に付属のkeytoolコマンドでは、PEMのEND行の前に空行のあるCSRができます。
    -- (IIDA Yosiaki) 2010-10-01 16:53:24
  • ある顧客から問合せがあり、asn1parseで中を見てみたら、こんなだった。
    0:d=0 hl=4 l=3289 cons: SEQUENCE
    4:d=1 hl=2 l= 9 prim: OBJECT :pkcs7-signedData
    15:d=1 hl=4 l=3274 cons: cont [ 0 ]
    19:d=2 hl=4 l=3270 cons: SEQUENCE
    23:d=3 hl=2 l= 1 prim: INTEGER :01
    26:d=3 hl=2 l= 11 cons: SET
    28:d=4 hl=2 l= 9 cons: SEQUENCE
    30:d=5 hl=2 l= 5 prim: OBJECT :sha1
    37:d=5 hl=2 l= 0 prim: NULL
    39:d=3 hl=4 l=1929 cons: SEQUENCE
    43:d=4 hl=2 l= 9 prim: OBJECT :pkcs7-data
    54:d=4 hl=4 l=1914 cons: cont [ 0 ]
    58:d=5 hl=4 l=1910 prim: OCTET STRING [HEX DUMP]:3082...
    1972:d=3 hl=4 l=1040 cons: cont [ 0 ]
    1976:d=4 hl=4 l=1036 cons: SEQUENCE
    1980:d=5 hl=4 l= 756 cons: SEQUENCE
    1984:d=6 hl=2 l= 3 cons: cont [ 0 ]
    1986:d=7 hl=2 l= 1 prim: INTEGER :02
    1989:d=6 hl=2 l= 8 prim: INTEGER :0F182A03470CDA7F
    1999:d=6 hl=2 l= 13 cons: SEQUENCE
    2001:d=7 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption
    2012:d=7 hl=2 l= 0 prim: NULL
    2014:d=6 hl=2 l= 95 cons: SEQUENCE
    2016:d=7 hl=2 l= 11 cons: SET
    2018:d=8 hl=2 l= 9 cons: SEQUENCE
    2020:d=9 hl=2 l= 3 prim: OBJECT :countryName
    2025:d=9 hl=2 l= 2 prim: PRINTABLESTRING :JP
    2029:d=7 hl=2 l= 37 cons: SET
    2031:d=8 hl=2 l= 35 cons: SEQUENCE
    2033:d=9 hl=2 l= 3 prim: OBJECT :organizationName
    2038:d=9 hl=2 l= 28 prim: PRINTABLESTRING :...
    2068:d=7 hl=2 l= 41 cons: SET
    2070:d=8 hl=2 l= 39 cons: SEQUENCE
    2072:d=9 hl=2 l= 3 prim: OBJECT :commonName
    2077:d=9 hl=2 l= 32 prim: PRINTABLESTRING :...
    2111:d=6 hl=2 l= 30 cons: SEQUENCE
    2113:d=7 hl=2 l= 13 prim: UTCTIME :091207063356Z
    2128:d=7 hl=2 l= 13 prim: UTCTIME :101210145959Z
    2143:d=6 hl=3 l= 138 cons: SEQUENCE
    2146:d=7 hl=2 l= 11 cons: SET
    2148:d=8 hl=2 l= 9 cons: SEQUENCE
    2150:d=9 hl=2 l= 3 prim: OBJECT :countryName
    2155:d=9 hl=2 l= 2 prim: PRINTABLESTRING :JP
    2159:d=7 hl=2 l= 14 cons: SET
    2161:d=8 hl=2 l= 12 cons: SEQUENCE
    2163:d=9 hl=2 l= 3 prim: OBJECT :stateOrProvinceName
    2168:d=9 hl=2 l= 5 prim: PRINTABLESTRING :...
    2175:d=7 hl=2 l= 19 cons: SET
    2177:d=8 hl=2 l= 17 cons: SEQUENCE
    2179:d=9 hl=2 l= 3 prim: OBJECT :localityName
    2184:d=9 hl=2 l= 10 prim: PRINTABLESTRING :...
    2196:d=7 hl=2 l= 24 cons: SET
    2198:d=8 hl=2 l= 22 cons: SEQUENCE
    2200:d=9 hl=2 l= 3 prim: OBJECT :organizationName
    2205:d=9 hl=2 l= 15 prim: PRINTABLESTRING :EXAMPLE CO.,LTD
    2222:d=7 hl=2 l= 27 cons: SET
    2224:d=8 hl=2 l= 25 cons: SEQUENCE
    2226:d=9 hl=2 l= 3 prim: OBJECT :organizationalUnitName
    2231:d=9 hl=2 l= 18 prim: PRINTABLESTRING :Information System
    2251:d=7 hl=2 l= 31 cons: SET
    2253:d=8 hl=2 l= 29 cons: SEQUENCE
    2255:d=9 hl=2 l= 3 prim: OBJECT :commonName
    2260:d=9 hl=2 l= 22 prim: PRINTABLESTRING :web-opas.example.co.jp
    2284:d=6 hl=3 l= 159 cons: SEQUENCE
    2287:d=7 hl=2 l= 13 cons: SEQUENCE
    2289:d=8 hl=2 l= 9 prim: OBJECT :rsaEncryption
    2300:d=8 hl=2 l= 0 prim: NULL
    2302:d=7 hl=3 l= 141 prim: BIT STRING
    2446:d=6 hl=4 l= 290 cons: cont [ 3 ]
    2450:d=7 hl=4 l= 286 cons: SEQUENCE
    2454:d=8 hl=2 l= 14 cons: SEQUENCE
    2456:d=9 hl=2 l= 3 prim: OBJECT :X509v3 Key Usage
    2461:d=9 hl=2 l= 1 prim: BOOLEAN :255
    2464:d=9 hl=2 l= 4 prim: OCTET STRING [HEX DUMP]:030205A0
    2470:d=8 hl=2 l= 19 cons: SEQUENCE
    2472:d=9 hl=2 l= 3 prim: OBJECT :X509v3 Extended Key Usage
    2477:d=9 hl=2 l= 12 prim: OCTET STRING [HEX DUMP]:300A06082B06010505070301
    2491:d=8 hl=2 l= 29 cons: SEQUENCE
    2493:d=9 hl=2 l= 3 prim: OBJECT :X509v3 Subject Key Identifier
    2498:d=9 hl=2 l= 22 prim: OCTET STRING [HEX DUMP]:0414816CAA909721E655BE744C1C7E584E67B3E0CDE1
    2522:d=8 hl=2 l= 31 cons: SEQUENCE
    2524:d=9 hl=2 l= 3 prim: OBJECT :X509v3 Authority Key Identifier
    2529:d=9 hl=2 l= 24 prim: OCTET STRING [HEX DUMP]:30168014309A00579944636BC9B2F23D8D836B3BD79DEF64
    2555:d=8 hl=2 l= 87 cons: SEQUENCE
    2557:d=9 hl=2 l= 3 prim: OBJECT :X509v3 Certificate Policies
    2562:d=9 hl=2 l= 80 prim: OCTET STRING [HEX DUMP]:304E304C060A2A83088C9B1B64856501303E303C06082B06010505070201163068747470733A2F2F7265706F312E7365636F6D74727573742E6E65742F73706370702F7066772F70667773723263612F
    2644:d=8 hl=2 l= 75 cons: SEQUENCE
    2646:d=9 hl=2 l= 3 prim: OBJECT :X509v3 CRL Distribution Points
    2651:d=9 hl=2 l= 68 prim: OCTET STRING [HEX DUMP]:30423040A03EA03C863A687474703A2F2F7265706F312E7365636F6D74727573742E6E65742F73706370702F7066772F70667773723263612F66756C6C63726C2E63726C
    2721:d=8 hl=2 l= 17 cons: SEQUENCE
    2723:d=9 hl=2 l= 9 prim: OBJECT :Netscape Cert Type
    2734:d=9 hl=2 l= 4 prim: OCTET STRING [HEX DUMP]:03020640
    2740:d=5 hl=2 l= 13 cons: SEQUENCE
    2742:d=6 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption
    2753:d=6 hl=2 l= 0 prim: NULL
    2755:d=5 hl=4 l= 257 prim: BIT STRING
    3016:d=3 hl=4 l= 273 cons: SET
    3020:d=4 hl=4 l= 269 cons: SEQUENCE
    3024:d=5 hl=2 l= 1 prim: INTEGER :01
    3027:d=5 hl=2 l= 107 cons: SEQUENCE
    3029:d=6 hl=2 l= 95 cons: SEQUENCE
    3031:d=7 hl=2 l= 11 cons: SET
    3033:d=8 hl=2 l= 9 cons: SEQUENCE
    3035:d=9 hl=2 l= 3 prim: OBJECT :countryName
    3040:d=9 hl=2 l= 2 prim: PRINTABLESTRING :JP
    3044:d=7 hl=2 l= 37 cons: SET
    3046:d=8 hl=2 l= 35 cons: SEQUENCE
    3048:d=9 hl=2 l= 3 prim: OBJECT :organizationName
    3053:d=9 hl=2 l= 28 prim: PRINTABLESTRING :...
    3083:d=7 hl=2 l= 41 cons: SET
    3085:d=8 hl=2 l= 39 cons: SEQUENCE
    3087:d=9 hl=2 l= 3 prim: OBJECT :commonName
    3092:d=9 hl=2 l= 32 prim: PRINTABLESTRING :...
    3126:d=6 hl=2 l= 8 prim: INTEGER :0F182A03470CDA7F
    3136:d=5 hl=2 l= 9 cons: SEQUENCE
    3138:d=6 hl=2 l= 5 prim: OBJECT :sha1
    3145:d=6 hl=2 l= 0 prim: NULL
    3147:d=5 hl=2 l= 13 cons: SEQUENCE
    3149:d=6 hl=2 l= 9 prim: OBJECT :rsaEncryption
    3160:d=6 hl=2 l= 0 prim: NULL
    3162:d=5 hl=3 l= 128 prim: OCTET STRING [HEX DUMP]:...
    -- (IIDA Yosiaki) 2010-11-18 17:23:28
  • DNのうちOの型だけをT61STRINGにし、unstructuredNameの値に「FALCON Component/X SSL 2002 00」という値を設定するウェブ・サーバーがある模様。 -- (IIDA Yosiaki) 2011-03-08 11:08:13
最終更新:2011年03月08日 11:08