Iyini ifayela le-PEM?

Indlela yokuvula, ukuhlela, nokuguqula amafayela we-PEM

Ifayela elinesandiso sefayili le-PEM ifayela leSikhathi seMeyili esithuthukisiwe sobumfihlo esetshenziselwa ukuthumela i-imeyili ngasese. Umuntu othola le imeyili angaqiniseka ngokuthi umlayezo awuzange ushintshwe ngesikhathi sokudluliselwa kwawo, awubonwanga kunoma ubani omunye, futhi uthunyelwe ngumuntu othi uyithumele.

Ifomethi ye-PEM ivele ekuhlanganyeleni kokuthumela idatha kanambambili nge-imeyili. Ifomethi ye-PEM ihlanganisa ikhodi kanambambili ne-base64 ukuze ikhona njengeyunithi ye-ASCII.

Ifomethi ye-PEM ishintshwe ngubuchwepheshe obusha futhi obuvikelekile kodwa isitsha se-PEM sisasetshenziswa namuhla ukubamba isitifiketi samafayela wesigunyaziso, izinkampani zomphakathi nezangasese, izitifiketi zezimpande, njll.

Qaphela: Amanye amafayela kwifomathi ye-PEM angase asebenzise isandiso sefayela ehlukile, njenge-CER noma i-CRT yezitifiketi, noma i-KEY yezihluthulelo zomphakathi noma zangasese.

Indlela Yokuvula Amafayela we-PEM

Izinyathelo zokuvula ifayela le-PEM zihlukile ngokuya kwesicelo esidinga yona kanye nesistimu yokusebenza oyisebenzisayo. Noma kunjalo, ungadinga ukuguqula ifayela lakho le-PEM ku-CER noma i-CRT ukuze ezinye zalezi zinhlelo zamukele ifayela.

Windows

Uma udinga ifayela le-CER noma i-CRT kumakhasimende we-imeyli e-Microsoft njenge-Outlook, vula ku-Inthanethi Explorer ukuthi ilayishwe ngokuzenzekelayo ku-database efanele. Iklayenti le-imeyili lingalisebenzisa ngokuzenzekelayo ukusuka lapho.

Ukuze ubone ukuthi yimaphi amafayela wesitifiketi alayishwa kukhompyutha yakho, futhi angenisa ngaphakathi ngesandla, sebenzisa imenyu ye-Inthanethi Explorer's ukuze ufinyelele Izinketho ze-Intanethi> Okuqukethwe> Izitifiketi .

Ukungenisa ifayela le-CER noma i-CRT ku-Windows, qala ngokuvula i-Microsoft Management Console ebhokisini lebhokisi le-Run (sebenzisa ukusinqamulela kwekhibhodi yeWindows Key + R ukungena mmc ). Ukusuka lapho, iya kufayili> Engeza / Susa i-Snap-in ... bese ukhetha Izitifiketi ukusuka kukholomu kwesokunxele, bese u- Faka> inkinobho maphakathi newindi. Khetha i- akhawunti yekhompyutha kwesikrini esilandelayo, bese uhamba ngokusebenzisa idijithali, ukhetha ikhompyutha yendawo uma ubuzwa.

Kanye "Izitifiketi" zilayishwe ngaphansi kokuthi "Umsuka wekhonsoli," wandise ifolda futhi uchofoze iziphathimandla eziqinisekisiwe ze-Certified Root Certification , bese ukhetha Yonke Imisebenzi> Ngenisa ....

i-macOS

Umqondo ofanayo uqinisile kumaklayenti wakho we-imeyili ye-Mac njengoba ku-Windows eyodwa; sebenzisa i-Safari ukuba ifayela le-PEM lingeniswe ku-Access Keychain.

Ungaphinda ungene izitifiketi ze-SSL ngefayela> Izinto Zokungenisa ... imenyu ekufinyeleleni kwe-Keychain. Khetha Isistimu kusuka kwimenyu yokudonsa bese ulandela ukufakwa kwesikrini.

Uma lezi zindlela zingasebenzi ukufaka ifayela le-PEM ku-macOS, ungazama umyalo olandelayo:

ukuphepha kungenise i-yourfile.pem -k ~ / Library / Keychains / login.keychain

Linux

Sebenzisa lo myalelo we-keytool ukubuka okuqukethwe kwefayela le-PEM ku-Linux:

keytool -printcert -file yourfile.pem

Landela lezi zinyathelo uma ufuna ukungenisa ifayela le-CRT kwisitoreji segunya lesitifiketi esethembekile seLinux (bheka indlela yokuguqula i-PEM kuya kwe-CRT esigabeni esilandelayo ngezansi uma unayo ifayela le-PEM esikhundleni):

  1. Hamba uye / usr / share / ca-izitifiketi / .
  2. Dala ifolda lapho (isibonelo, sudo mkdir / usr / share / ca-izitifiketi / umsebenzi ).
  3. Kopisha ifayela le-.CRT kuleyo folda esanda kudalwa. Uma ungathanda ukungenzi ngesandla, ungasebenzisa lo myalo kunalokho: sudo cp yourfile.crt /usr/share/ca-certificates/work/yourfile.crt .
  4. Qiniseka ukuthi izimvume zihlelwe kahle (755 kwifolda kanye no-644 yefayela).
  5. Qalisa umyalo we- sudo update-ca-certificates .

I-Firefox ne-Thunderbird

Uma ifayili le-PEM idinga ukungeniswa kuklayenti le-imeyili le-Mozilla njengoThunderbird, kungadingeka uqale ukuthumela ifayela le-PEM ngaphandle kwe-Firefox. Vula imenyu ye-Firefox bese ukhetha Izinketho . Iya Okuthuthukisiwe> Izitifiketi> Buka Izitifiketi> Izitifiketi Zakho bese ukhetha okudingayo ukuthekelisa, bese ukhetha Isipele ....

Khona-ke, ku-Thunderbird, vula imenyu bese uchofoza noma thinta Izinketho . Zula ku- Advanced> Izitifiketi> Lawula Izitifiketi> Izitifiketi Zakho> Ngenisa .... Kusuka ku "Igama lefayela:" ingxenye yewindi lokungenisa, khetha amafayela wesitifiketi ukusuka phansi, bese uthola futhi uvule ifayela le-PEM.

Ukuze ungenise ifayela le-PEM ibe yi-Firefox, vele ulandele izinyathelo ezifanayo ongayithumela ngazo, kepha khetha ukungenisa ... esikhundleni se- Backup ... inkinobho.

I-Java KeyStore

Bheka le fayili yokukhuphuka komthamo ekungeneni ifayela le-PEM kwi-Java KeyStore (JKS) uma udinga ukwenza lokho. Enye indlela ongase isebenze ukusebenzisa leli thuluzi le-keyutil.

Indlela yokuguqula ifayela le-PEM

Ngokungafani namafomethi amaningi efayela angaguqulwa ngethuluzi lokuguqulwa kwefayela noma iwebhusayithi , udinga ukufaka imiyalo ekhethekile ngokumelene nohlelo oluthile ukuze uguqule ifomethi yefayili ye-PEM nakweminye eminye ifomethi.

Guqula i-PEM ku-PPK nge-PuTTYGen. Khetha Umthwalo ukusuka ngakwesokudla kohlelo, setha uhlobo lwefayili ukuba ube yiliphi ifayela (*. *), Bese upheqa bese uvula ifayela lakho le-PEM. Khetha Ukugcina ukhiye wangasese ukuze wenze ifayela le-PPK.

Nge-OpenSSL (thola i-Windows version lapha), ungaguqula ifayela le-PEM ku-PFX ngomyalo olandelayo:

openssl pkcs12 -inkey yourfile.pem -ku-yourfile.cert -export -out yourfile.pfx

Uma unefayela le-PEM elidinga ukuguqulwa ku-CRT, njengokufana ne-Ubuntu, sebenzisa lo myalo nge-OpenSSL:

i-openssl x509 -ku-yourfile.pem -inhlobonhlobo ye-PEM -kuyi-yourfile.crt

I-OpenSSL iphinde isekele ukuguqula i - .PEM kuya ku - P12 (PKCS # 12, noma i - Public Key Cryptography # 12), kodwa usethe isandiso sefayela ".TXT" ekupheleni kwefayela ngaphambi kokusebenzisa lo myalo:

openssl pkcs12-phuma -inkey thyfile.pem.txt -in-yourfile.pem.txt -yakho i-yourfile.p12

Bheka isixhumanisi se-Stack Overflow ngaphezulu mayelana nokusebenzisa ifayela le-PEM ngeJava KeyStore uma ufuna ukuguqula ifayela ku-JKS, noma lokhu okufundiswa ku-Oracle ukungenisa ifayela kwi-Java truststore.

Ukwaziswa okwengeziwe nge-PEM

Isici sokuthembeka kwedatha yefomethi ye-Private Enhanced Certificate ye-Imeyili isebenzisa ama-RSA-MD2 kanye no-RSA- MD5 umgudu womlayezo wokuqhathanisa umlayezo ngaphambi nangemva kokuba uthunyelwe, ukuqinisekisa ukuthi awuzange uhambisane nendlela.

Ekuqaleni kwefayela le-PEM liyinhloko efunda ----- QALA [ilebula] ----- , futhi ekupheleni kwedatha kuyinyawo efanayo efanayo: ----- END [ilebula] - ----. Ingxenye ethi "[ilebula]" ichaza umlayezo, ngakho-ke ingase ifunde ISICELO SOKUQALA, ISICERTIFICATE, noma i- CERTIFICATE .

Nasi isibonelo:

----- ZIQALA KEY PRIVATE ----- MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAMLgD0kAKDb5cFyP jbwNfR5CtewdXC + kMXAWD8DLxiTTvhMW7qVnlwOm36mZlszHKvsRf05lT4pegiFM 9z2j1OlaN + ci / X7NU22TNN6crYSiN77FjYJP464j876ndSxyD + rzys386T + 1r1aZ aggEdkj1TsSsv1zWIYKlPIjlvhuxAgMBAAECgYA0aH + T2Vf3WOPv8KdkcJg6gCRe yJKXOWgWRcicx / CUzOEsTxmFIDPLxqAWA3k7v0B + 3vjGw5Y9lycV / 5XqXNoQI14j y09iNsumds13u5AKkGdTJnZhQ7UKdoVHfuP44ZdOv / rJ5 / VD6F4zWywpe90pcbK + AWDVtusgGQBSieEl1QJBAOyVrUG5l2yoUBtd2zr / kiGm / DYyXlIthQO / A3 / LngDW 5 / ydGxVsT7lAVOgCsoT + 0L4efTh90PjzW8LPQrPBWVMCQQDS3h / FtYYd5lfz + FNL 9CEe1F1w9l8P749uNUD0g317zv1tatIqVCsQWHfVHNdVvfQ + vSFw38OORO00Xqs9 1GJrAkBkoXXEkxCZoy4PteheO / 8IWWLGGr6L7di6MzFl1lIqwT6D8L9oaV2vynFT DnKop0pa09Unhjyw57KMNmSE2SUJAkEArloTEzpgRmCq4IK2 / NpCeGdHS5uqRlbh 1VIa / xGps7EWQl5Mn8swQDel / YP3WGHTjfx7pgSegQfkyaRtGpZ9OQJAa9Vumj8m JAAtI0Bnga8hgQx7BhTQY4CadDxyiRGOGYhwUzYVCqkb2sbVRH9HnwUaJT7cWBY3 RnJdHOMXWem7 / w == ----- UKUPHELA KEY PRIVATE -----

Ifayela elilodwa le-PEM lingaba nezitifiketi eziningi, lapho kwenzeka khona "END" ne "BEGIN" izingxenye zomakhelwane nomunye.

Ingabe Ifayela Lakho Alikavuli?

Esinye isizathu sokuthi ifayela lakho alivuli ngezindlela ezichazwe ngenhla ukuthi awukho ngempela ukubhekana nefayela le-PEM. Kungenzeka ukuthi ube nefayela elisebenzisa nje isandiso sefayela lesipelingi. Uma kunjalo, akudingeki ukuthi amafayela amabili ahlobene noma asebenze nezinhlelo ezifanayo zesofthiwe.

Isibonelo, i- PEF ibukeka kabi kakhulu njenge-PEM kodwa kunalokho iyingxenye yefomethi yefayela le-Pentax Raw Image noma ifomethi ye-Portable Embosser. Landela leso sixhumanisi ukuze ubone ukuthi ungavula kanjani noma uguqule amafayela we-PEF, uma yilokho onakho ngempela.

Uma usebenzisana nefayela eliyi-KEY, qaphela ukuthi akuwona wonke amafayela aphelile .UMUNYE usefomathi echazwe kuleli khasi. Kungenzeka ukuthi kube amafayili e-Software License Key asetshenziswa lapho ubhalisa izinhlelo zesofthiwe njenge-LightWave, noma amafayela we-Keynote Presentation adalwe yi-Apple Keynote.

Uma unesiqiniseko sokuthi unayo ifayela le-PEM kodwa unenkinga yokuvula noma ukuyisebenzisa, bheka Thola Usizo Olwengeziwe ngolwazi mayelana nokuxhumana nami kumanethiwekhi omphakathi noma nge-imeyili, ukuthumela kumaforamu wokusekela we-tech, nokuningi. Ngitshele ukuthi yiziphi izinhlobo zezinkinga onakho futhi ngizobona ukuthi ngingenzani ukusiza.