Re: how to create keystore by using NSS certutil (Hubert Kario

Hubert Kario <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On Thursday 20 August 2015 11:06:38 Kelly wrote:
> On Tuesday 18 August 2015 14:28:35 Kelly wrote:
> > Thanks again.
> > 
> >              i input the command you said, and it reply "Warning: ignoring
> > 
> > private key. Consider to use pk12util" i want to know :
> >       1, the cert has wrotten into it?
> 
> the one in the file
> 
> certutil can import just certificate, keys need to be imported from PKCS#12
> files
> 
> see pkcs12 man page for openssl utility that allows you to convert a PEM
> format cert and key pair to a pkcs12 file
> 
> then use pk12util to import it to NSS database
> 
> 
> can you explaine the keys you said in "keys need to be imported from PKCS#12
> files" ?

the PEM files you have and PKCS#12 you need to create are just file formats 
storing the same data

think .doc and .odp for text documents

> it represent private key or the key needs when you install a p12
> cert?

PKCS#12 is a just a bag holding the certificates and keys, the certificates 
themselves are still X.509 certificates and the private keys are still PKCS#8 
internally.
 
> i have another question: when use certutil to create a nssdb,  there will
> create cert9.db, key4.db and pkcs11.txt in home/nssdb/ and install cert an
> app need, and then if i cpoy those file to another pc,  can it work ?

yes, the nssdb is portable and can be copied between computers, including ones 
that have different CPU architectures

> if
> can, the cert will no need to exist.

yes, if you have the certificate in nssdb you don't need it as a separate file
 
> in fact i want to write cert into system store,
> in windows i can use API CertOpenSystemStore,
> but in linux,  i can not.

yes, it's not entirely standardised yet on Linux systems

But the current proposal (and something already used by RHEL, Fedora and 
gnome-keyring) is to have the system-wide cert store in /etc/pki/nssdb. User 
applications open this database and if they need to store certificates there, 
it will be transparently handled by NSS by writing it to ~/.pki/nssdb.

In other words, by opening /etc/pki/nssdb you're opening two databases at the 
same time - the one in /etc and the one in user home directory - getting both 
the system certificates and user certificates



unrelated to crypto: when replying please prefix the lines you quote with 
either ">" or "|", lack of them makes replying to you very hard

> the QCA  (Qt Cryptographic Architecture ) surpport system store, i  send my
> question to mail list of it, but no reply.
> >       2, the cert i wrote has private key,  like format follow:
> >                ------BEGIN CERTIFICATE-----
> >                
> >                ------END CERTIFICATE-----
> >              
> >              ------BEGIN EC PRIVATE KEY-----
> >         
> >         ------END EC PRIVATE KEY-----
> > 
> > how can i to deal with it?
> 
> see above
> 
> > 3, can you help me to packaged the certutil tool into API function, then i
> > can use it in my QT app?
> 
> sorry, I'm not familiar with C/C++ API of NSS, I can only suggest reading
> sources of certutil, pk12util and online documentation here:
> https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/Reference
> 
> > but i use command "certutil -L  -n  nick-name", it reply "certutil:
> > function failed: SEC_ERROR_LEGACY_DATABASE: The certificate/key database
> > is in old, unsupported format."
> 
> you need to always specify the database using -d otherwise you're using the
> default from ~/.netscape
> 
> Currently a user default database is stored in ~/.pki/nssdb
> 
> > how can i get the cert i wrote in?
> > 
> > 
> > 
> > i use command ""certutil -L -a  -n  nick-name  -d sql:./nssdb/"
> > 
> >  it display the cert content with not private key
> 
> to export the key you must use pk12util, there's no other standard NSS tool
> to do that
> 
> >                                                         kelly
> 
>  command "certutil -A -d sql:./nssdb/ -n cert-nickname -a >> >> -i
> cert-in-ascii.pem" like "certutil -A -d sql:./nssdb/ -n cert-nickname >> >>
> -a -i>> >> >> /home/l/Desktop/ASUE1.cer" it said "certutil -A: trust is
> required for >> >> >> >> this command (-t)" >> >> and then i input
> "certutil -A -t -d sql:./nssdb/ -n cert-nickname -a -i >> >>
> /home/l/Desktop/ASUE1.cer" it reply "certutil: function failed: >> >>
> SEC_ERROR_LEGACY_DATABASE: The certificate/key database is in old, >> >>
> unsupported format." >> > >> >-t requires a parameter, try >> > >> >-t ',,'
> >>

-- 
Regards,
Hubert Kario
Quality Engineer, QE BaseOS Security team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 99/71, 612 45, Brno, Czech Republic

_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAABCgAGBQJV1bHHAAoJEJKo0bgB0vX1VJ8P/1gU71nHxUPUrQBoq9ll6yxv
YvKQVpwOCnX/GYNhjHvCTVYIYaEPAWPFF3KjjjsO6FchlitAvP5XQIdCnDlYy5m4
J39iKtDB9q/96etSOVxNHrVEKCNsDE7tpuZRBuhpYeHZbSxyXL5lM8HXceo4pPWi
sixsP+y6zXG23k13hJq9BA2TfDA57OKkwQk4fv3r2+SqdrVJiY2ZbMlTXP4x31pU
DUOL1JV4jdMxb8QcNjX8QpeAEYDcPvMEgb3g7O1pQp8xHvmoT44W+vhWkb+GImuS
DA97K832+017rNAdOmbE5w2uG4r7fEUDluVZQjhnmM2AoRPyyneNP4YWeEHdWNUU
f4FvJcVk8Ae77TwBGaBaNpcHkA8Ob67wYIS5b0pgCd+wjim2oEIoF7ngeLptjS3+
XGCo0YEZxoDV1qVbdcgnM74taoYVeNqei12mxOH8QgcOVCsDRIdlRoXa5VnhpTwO
WBm6ZHouxoUTgf5p9YkeBQ0IC1UjwXuJoiLP7Wy0rKbS4Bg2AyQF8uPSYU4sOdtr
S0UEoLtLRt5XiI81LV60M/zZ3fZ+/oN5QYoAz3FTZtJ4NF3+gC00WGG3RvS2bnnA
CNJHJoeS7jMJ+9Gtt94epahdWtubdq+WqzF2zP4htpREOU103Rc6cOC6mFPOTGVC
09dLzmnTLYwDqLdzc0j3
=UvQv
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.