我想创建CX509CertificateRequestPKC 带有初始值的证书 我想使用X509RequestInheritOptions.InheritNewSimilarkey在原始证书的密钥对存在的地方生成新的密钥对 但我得到错误CertEnroll::CX509CertificateRequestPkcs7::InitializeFromCertificate:请求的属性值为空。0x80094004(-2146877436 CERTSRV_E_属性为空) 这是我的密码
X509Store store = new X509Store(StoreLocation.CurrentUser);
store.Open(OpenFlags.ReadOnly);
foreach (X509Certificate2 c in store.Certificates)
{
var cert2 = c.Subject;
if (cert2.Contains("CN=test"))
{
var objPkcs72 = new CX509CertificateRequestPkcs7();
string strCertificate = Convert.ToBase64String(c.RawData);
var inheritOptions = X509RequestInheritOptions.InheritNewSimilarKey ;
objPkcs72.InitializeFromCertificate(X509CertificateEnrollmentContext.ContextUser, false, strCertificate, EncodingType.XCN_CRYPT_STRING_BASE64, inheritOptions);
ISignerCertificate signer = new CSignerCertificate();
CERTENROLLLib.CSignerCertificate signer2 = new CERTENROLLLib.CSignerCertificate();
signer2.Initialize(false, X509PrivateKeyVerify.VerifyAllowUI, EncodingType.XCN_CRYPT_STRING_BASE64, strCertificate);
objPkcs72.SignerCertificate = signer2;
string c2 = "";
objEnroll.InitializeFromRequest(objPkcs72);
var message2 = objEnroll.CreateRequest(EncodingType.XCN_CRYPT_STRING_BASE64);
var iDisposition = objCertRequest.Submit(CR_IN_BASE64 | CR_IN_FORMATANY, message2, templateName, CAAddress);
string c3 = objCertRequest.GetCertificate(CR_IN_BASE64 | CR_IN_FORMATANY);
X509Certificate2 cert = new X509Certificate2(LoadFromCertBase64String(c2));
objEnroll.InstallResponse(InstallResponseRestrictionFlags.AllowNone, c3, EncodingType.XCN_CRYPT_STRING_BASE64, "");
}
}
目前没有回答
相关问题 更多 >
编程相关推荐