Yintoni iFayile yePEM?

Indlela yokuvula, ukuhlela, nokuguqula iifayile ze-PEM

Ifayili enefayile yePEM isandiso seFayile yeSatifikethi seMeyili esithuthukisiwe esasetyenziselwa ukuthumela i-imeyili ngasese. Umntu ofumana le imeyile unokuqiniseka ukuba umyalezo awuzange utshintshwe ngexesha lokudluliselwa kwawo, akazange aboniswe nakubani na omnye, kwaye uthunyelwe ngumntu othi mabathumele.

Ifomathi yePEM yavela kwiinkcenkceshelo zokuthumela idatha yebinary nge-imeyile. Ifomathi yePEM idibanisa ibhonari kunye ne-base64 ukuze ikhona njengomtya we-ASCII.

Ifom ye-PEM ithathelwe indawo yimibuchwephesha entsha kunye nekhuselekileyo kodwa isitsha se-PEM sisasetyenziswa namhlanje ukuba sibambe isitifiketi segunya, izicwangciso zoluntu kunye nezizimeleyo, izatifikethi zengcambu, njl njl.

Qaphela: Ezinye iifayile kwifomathi ye-PEM zingasetyenziselwa ukusebenzisa isandiso seefayile ezahlukeneyo, njenge-CER okanye i-CRT yeziqinisekiso, okanye i-KEY yezixhobo zoluntu okanye ezizimeleyo.

Indlela yokuvula iifayile ze-PEM

Amanyathelo okuvula ifayile ye-PEM ahluke ngokuxhomekeka kwisicelo esiludinga kunye nenkqubo yokusebenza oyisebenzisayo . Nangona kunjalo, unokufuna ukuguqula ifayile yakho ye-PEM kwi-CER okanye kwi-CRT ukuze ezinye zezi nkqubo zamukele i fayile.

Windows

Ukuba udinga ifayile ye-CER okanye i-CRT kumxhasi we-imeyile we-Microsoft njengo-Outlook, vula kwi-Internet Explorer ukuba ilayishwe ngokuzenzekelayo kwi-database efanelekileyo. Umthengi we-imeyile unokusebenzisa ngokuzenzekelayo ukusuka apho.

Ukubona ukuba yeyiphi iifayile zesitifiketi ezilayishiwe kwikhompyutheni yakho, kwaye ukuzithengela ngesandla, sebenzisa imenyu yeThuluzi le-Internet Explorer ukufikelela kwiinketho ze-Inthanethi> Okuqukethwe> Iziqinisekiso .

Ukungenisa ifayile ye-CER okanye i-CRT kwi-Windows, qalisa ngokuvula i-Microsoft Management Console ukusuka kwibhokisi yencoko yokusebenza (sebenzisa indlela yokuvala yekhibhodi ye- Windows Key + R ukungena mmc ). Ukusuka apho, iya kwi Fayile> Yongeza / Susa iStap-in ... kwaye ukhethe izatifikethi ukusuka kumkhola wesobunxele, kunye ne- Add> iqhosha phakathi kwe window. Khetha i- akhawunti yekhompyutheni kwiskrini elandelayo, uze uhambe nge-wizard, ukhethe ikhompyutha yendawo xa ubuzwa.

Emva kokuba "iiSatifikethi" zilayishwe phantsi kwe "Console Root," wandise ifolda kunye neqhosha lokunqakraza kwi- Trusted Root Certification Authority , kwaye ukhethe Zonke Imisebenzi> Ukungenisa ....

macOS

Ingcamango efanayo yinyaniso kumthengi wakho we-imeyile ye-Mac njengoko kunjalo kwi-Windows eyodwa; sebenzisa i-Safari ukuba ifayile ye-PEM ithunyelwe kwi-Keychain Access.

Ungaphinde ufake iziqinisekiso ze-SSL kwiFayile> Izinto zokungenisa izinto ... kwimenyu kwi-Keychain Access. Khetha I- System ukusuka kwimenyu ehlayo uze ulandele i-screen-prompts.

Ukuba ezi ndlela zingasebenzi ukuthumela ifayile yePEM kwi-macOS, unokuzama umyalelo olandelayo:

ukhuseleko lokungenisa yakho ifayile.pem -k ~ / iThala leencwadi / ii-Keychains / login.keychain

Linux

Sebenzisa lo myalelo we keytool ukujonga okuqukethwe kwefayile ye-PEM kwi-Linux:

keytool -printcert -file ifayile yakho.pem

Landela lamanyathelo ukuba ufuna ukungenisa ifayile ye-CRT kwisitoreji sokugunyazwa kwegunya le-Linux esithembekileyo (sibone indlela yokuguqula i-PEM ukuya kwi-CRT kwicandelo elilandelayo ngezantsi ukuba unayo ifayile ye-PEM endaweni):

  1. Jonga kwi / usr / share / certificates / ca-certificates / .
  2. Yakha ifolda apho (umzekelo, sudo mkdir / usr / share / cer-certificates / work ).
  3. Kopisha ifayile ye .CRT kule fayili entsha. Ukuba unqwenela ukukwenza ngesandla, ungasebenzisa lo myalelo esikhundleni: sudo cp yakhofile.crt /usr/share/ca-certificates/work/yourfile.crt .
  4. Qinisekisa ukuba iimvume zibekwe ngokuchanekileyo (755 kwifolda kunye no-644 kwifayile).
  5. Qalisa umyalelo we- sudo update-ca-certificates .

Firefox kunye neThunderbird

Ukuba ifayile ye-PEM idinga ukungeniswa kumthengi we-imeyile ye-Mozilla njengoTynderbird, kufuneka uqale ukuthumela iFM ifowuni ngaphandle kwe-Firefox. Vula imenyu ye-Firefox kwaye ukhethe Izinketho . Iya kwi- Advanced> Izatifikethi> Jonga izitifiketi> Izatifikethi zakho kwaye ukhethe lowo ufuna ukuzithumela, uze ukhethe iBackup ....

Emva koko, kwi-Thunderbird, vula imenyu kwaye nqakraza okanye uthephe Khetha . Jonga kwi- Advanced> Izatifikethi> Ukulawula izatifikethi> Izatifikethi zakho> Ukungenisa .... Ukusuka kwi "Ifayile yegama:" icandelo leWindows window, khetha iiFayile zeSatifikethi ukusuka ekuhlahleni, uze ufumane kwaye uvule ifayile ye-PEM.

Ukungenisa ifayile ye-PEM kwi-Firefox, landela amanyathelo afanayo oya kuthumela omnye, kodwa ukhethe Ukungenisa ... endaweni ye- Backup ... iqhosha.

Java KeyStore

Jonga lo mgca wokuThuthukiswa komgca wokungenisa ukungenisa ifayile ye-PEM kwi-Java KeyStore (JKS) ukuba ufuna ukwenza oko. Enye inketho engayisebenzisela ukusebenzisa le thuluzi le-keyutil.

Indlela yokuguqula ifayile ye-PEM

Ngokungafani nefomathi ezininzi zefayile ezingaguquleka ngeziko lokuguqulwa kwefayile okanye kwiwebhsayithi , kufuneka ufake imithetho ekhethekileyo malunga nenkqubo ethile ukwenzela ukuguqula ifom yefayile ye-PEM kwezinye iifom.

Guqulela i-PEM kwi-PPK ngePuTTYGen. Khetha Umthwalo ukusuka kwicala lasekunene lenkqubo, setha uhlobo lwefayili ukuba nayiphi na ifayile (*. *), Uze uphendule kwaye uvule ifayile yakho ye-PEM. Khetha Gcina ukhiye wobucala ukwenza ifayile ye-PPK.

Nge-OpenSSL (fumana ifayile yeWindows apha), unokuguqula ifayile ye-PEM kwi-PFX ngomyalelo olandelayo:

vulasl pkcs12 -kufake iifayile yakho.i -fayile yakho.cert-export -fayile yakho.pfx

Ukuba unefayile yePEM efuna ukuguqulwa kwi-CRT, njengokuba kunjalo neBuntu, sebenzisa lo myalelo nge-OpenSSL:

vulasl x509 -infayile yakho.pem -nxulumanisa i-PEM -yifayile yakho.crt

I-OpenSSL iphinde isekele ukuguqula iPEM kwi - .P12 (iPKCS # 12, okanye iProgram yoLuntu oluPhezulu lweNkcazo ye-Cryptography # 12), kodwa fakela "extension" ifayile yokwandisa ekupheleni kwefayili ngaphambi kokusebenzisa lo myalelo:

vulasl pkcs12--ngenisa -iyifayile yakho.pem.txt -fayile yakho.pem.txt -fayile yakho yefayile.12

Khangela ikhonkco lokukhupha i-Stack ngaphezulu malunga nokusebenzisa ifayile ye-PEM ngeJava KeyStore ukuba ufuna ukuguqula iifayile kwi-JKS, okanye le ngcaciso evela kwi-Oracle ukufaka ifayile kwi-truststore ye-Java.

Ulwazi olungakumbi kwi-PEM

Ubume beengqibelelo zobume befomathi yoBucala boBucala boBucala boBucala boBucala bobuSebenzi busebenzisa i-RSA-MD2 kunye ne-RSA- MD5 yesigidimi sokutya ukuthelekisa umyalezo ngaphambi nangemva kokuthunyelwa, ukuqinisekisa ukuba akuzange kuphazamiseke endleleni.

Ekuqaleni kwefayili ye-PEM yintloko efundwayo ----- QALISA [ilebula] ----- , kwaye ekupheleni kwedatha inyawo efana nale: ----- END [ilebula] - ----. Icandelo elithi "[ileyibhile]" lichaza umyalezo, ngoko unokufunda ISICWANGCISO ESIFUNDWAYO, ISICELO SESATIFIKETHI, okanye ISATIFIKETHI .

Nasi umzekelo:

----- LUQALA endleke PRIVATE ----- MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAMLgD0kAKDb5cFyP jbwNfR5CtewdXC + kMXAWD8DLxiTTvhMW7qVnlwOm36mZlszHKvsRf05lT4pegiFM 9z2j1OlaN + ci / X7NU22TNN6crYSiN77FjYJP464j876ndSxyD + rzys386T + 1r1aZ aggEdkj1TsSsv1zWIYKlPIjlvhuxAgMBAAECgYA0aH + T2Vf3WOPv8KdkcJg6gCRe yJKXOWgWRcicx / CUzOEsTxmFIDPLxqAWA3k7v0B + 3vjGw5Y9lycV / 5XqXNoQI14j y09iNsumds13u5AKkGdTJnZhQ7UKdoVHfuP44ZdOv / rJ5 / VD6F4zWywpe90pcbK + AWDVtusgGQBSieEl1QJBAOyVrUG5l2yoUBtd2zr / kiGm / DYyXlIthQO / A3 / LngDW 5 / ydGxVsT7lAVOgCsoT + 0L4efTh90PjzW8LPQrPBWVMCQQDS3h / FtYYd5lfz + FNL 9CEe1F1w9l8P749uNUD0g317zv1tatIqVCsQWHfVHNdVvfQ + vSFw38OORO00Xqs9 1GJrAkBkoXXEkxCZoy4PteheO / 8IWWLGGr6L7di6MzFl1lIqwT6D8L9oaV2vynFT DnKop0pa09Unhjyw57KMNmSE2SUJAkEArloTEzpgRmCq4IK2 / NpCeGdHS5uqRlbh 1VIa / xGps7EWQl5Mn8swQDel / YP3WGHTjfx7pgSegQfkyaRtGpZ9OQJAa9Vumj8m JAAtI0Bnga8hgQx7BhTQY4CadDxyiRGOGYhwUzYVCqkb2sbVRH9HnwUaJT7cWBY3 RnJdHOMXWem7 / w == ----- END endleke YABUCALA -----

Ifayili ye-PEM ingaqukatha izatifikethi ezininzi, apho i-"END" kunye "BEGIN" idibene nomnye ummelwane.

Ngaba Ifayile Yakho Ayisayi kuvulwa?

Esinye isizathu sokuba ifayile yakho ingavuli ngeendlela ezichazwe ngasentla kukuba awukwenzi ngokufanelekileyo nefayile yePEM. Kungenzeka ukuba ube nefayile esebenzisa nje ukongezwa kwefayile yespel. Xa kunjalo, akukho mfuneko yokuba iifayile ezimbini zihlobene okanye ukuba zisebenze kunye neeprogram ezifanayo.

Umzekelo, i- PEF ibheka iimeko ezinzima njengePEM kodwa kunokuba ibe yifom yefayile yePentax Raw Image okanye ifomathi ye-Portable Embosser. Landela loo nxu lumene ukuvula okanye ukuguqula iifayile ze-PEF, ukuba yilokho unayo.

Ukuba ujongene nefayili engundoqo, qaphela ukuba akuyizo zonke iifayile ezigqityiweyo .ZEY zifomathi ezichazwe kweli phepha. Basenokuthi babe yiifayile zeFayile zeFayile zeLayisense xa zisetyenziselwa iinkqubo zesofthiwe ezifana ne-LightWave, okanye iifayile ze-Keynote Presentation ezenziwe ngu-Apple Keynote.

Ukuba unesiqinisekiso sokuthi unayo ifayile ye-PEM kodwa unenkxwaleko yokuvula okanye ukuyisebenzisa, khangela Ufumane Uncedo olungakumbi malunga nokudibanisa kumanethiwekhi omphakathi okanye nge-imeyile, ukuthumela kwiiforam zenkxaso ye-tech, nokunye. Ndixelele ziphi iintlobo zeengxaki onayo kwaye ndiza kubona oko ndiyakwenza ukuze ndincede.