使用如下所示生成的 CA 时,openssl 1.1.1d 出现此错误:
openssl req -new -x509 -config ca.cnf -newkey rsa:4096 -sha256 -nodes -out ca-certificate.pem -outform PEM
openssl req -new -config client.cnf -newkey rsa:2048 -sha256 -nodes -out client-certificate.csr -outform PEM
openssl ca -batch -config ca.cnf -policy signing_policy -extensions signing_req -out client-certificate.pem -infiles client-certificate.csr
openssl pkcs12 -export -in client-certificate.pem -inkey client-private-key.pem -password pass:xxx -chain -CAfile ca-certificate.pem -out client.p12 -name "Client Certificate"
Error invalid ca certificate getting chain
这与 v1.0.2 配合良好。如果有解决方法,请告知。