{"id":367,"date":"2023-11-26T21:31:23","date_gmt":"2023-11-26T13:31:23","guid":{"rendered":"http:\/\/8.141.4.74\/?p=367"},"modified":"2024-03-28T13:40:55","modified_gmt":"2024-03-28T05:40:55","slug":"%e6%9e%84%e5%bb%ba%e7%a7%81%e6%9c%89ca%ef%bc%9a%e4%bc%81%e4%b8%9a%e7%ba%a7%e8%af%81%e4%b9%a6%e9%a2%81%e5%8f%91%e4%b8%8e%e7%ae%a1%e7%90%86%e7%ad%96%e7%95%a5","status":"publish","type":"post","link":"http:\/\/8.141.4.74\/?p=367","title":{"rendered":"\u6784\u5efa\u79c1\u6709CA\uff1a\u4f01\u4e1a\u7ea7\u8bc1\u4e66\u9881\u53d1\u4e0e\u7ba1\u7406\u7b56\u7565"},"content":{"rendered":"<h1>\u5efa\u7acb\u79c1\u6709CA\u9881\u53d1\u8bc1\u4e66<\/h1>\n<h2>1.\u793a\u4f8b\u6587\u4ef6\u4ecb\u7ecd<\/h2>\n<pre><code class=\"language-bash\">#\u67e5\u770bOpenSSL\u8bc1\u4e66\u9881\u53d1\u673a\u6784(CA)\u7684\u914d\u7f6e\u6587\u4ef6\u7684\u793a\u4f8b\u6587\u4ef6\n[root@centos8 CA]#vim \/etc\/pki\/tls\/openssl.cnf \u4e0b\u9762\u662f\u4e00\u4e9b\u5173\u952e\u5185\u5bb9\n[ CA_default ]\n\ndir     = \/etc\/pki\/CA       # Where everything is kept\ncerts       = $dir\/certs        # Where the issued certs are kept\ncrl_dir     = $dir\/crl      # Where the issued crl are kept\ndatabase    = $dir\/index.txt    # database index file.\n#unique_subject = no            # Set to &#039;no&#039; to allow creation of\n                    # several certs with same subject.\nnew_certs_dir   = $dir\/newcerts     # default place for new certs.\n\ncertificate = $dir\/cacert.pem   # The CA certificate\nserial      = $dir\/serial       # The current serial number\ncrlnumber   = $dir\/crlnumber    # the current crl number\n                    # must be commented out to leave a V1 CRL\ncrl     = $dir\/crl.pem      # The current CRL\nprivate_key = $dir\/private\/cakey.pem# The private key\n\nx509_extensions = usr_cert      # The extensions to add to the cert\n\n# Comment out the following two lines for the &quot;traditional&quot;\n# (and highly broken) format.\nname_opt    = ca_default        # Subject Name options\ncert_opt    = ca_default        # Certificate field options\n\n# Extension copying option: use with caution.\n# copy_extensions = copy\n\n# Extensions to add to a CRL. Note: Netscape communicator chokes on V2 CRLs\n# so this is commented out by default to leave a V1 CRL.\n# crlnumber must also be commented out to leave a V1 CRL.\n# crl_extensions    = crl_ext\n\ndefault_days    = 365           # how long to certify for\ndefault_crl_days= 30            # how long before next CRL\ndefault_md  = sha256        # use SHA-256 by default\npreserve    = no            # keep passed DN ordering\n\n[ policy_match ]\ncountryName     = match\nstateOrProvinceName = match\norganizationName    = match\norganizationalUnitName  = optional\ncommonName      = supplied\nemailAddress        = optional\n\n#\u8fd9\u4e2a\u6587\u4ef6\u662fOpenSSL\u8bc1\u4e66\u9881\u53d1\u673a\u6784(CA)\u7684\u914d\u7f6e\u6587\u4ef6\u7684\u793a\u4f8b\u3002\u5b83\u5b9a\u4e49\u4e86\u751f\u6210CA\u548c\u8bc1\u4e66\u6240\u9700\u7684\u5404\u79cd\u53c2\u6570\u548c\u8def\u5f84\u3002\ndir\uff1a\u5b58\u50a8\u6240\u6709\u5185\u5bb9\u7684\u76ee\u5f55\uff0c\u6240\u6709\u5176\u4ed6\u7684\u76f8\u5bf9\u8def\u5f84\u90fd\u662f\u57fa\u4e8e\u6b64\u76ee\u5f55\u3002\ncerts\uff1a\u5df2\u9881\u53d1\u8bc1\u4e66\u7684\u5b58\u50a8\u4f4d\u7f6e\u3002\ncrl_dir\uff1a\u5df2\u9881\u53d1\u8bc1\u4e66\u64a4\u9500\u5217\u8868\uff08CRL\uff09\u7684\u5b58\u50a8\u4f4d\u7f6e\u3002\ndatabase\uff1a\u7d22\u5f15\u6570\u636e\u5e93\u6587\u4ef6\u7684\u4f4d\u7f6e\uff0c\u5b83\u7528\u6765\u8ffd\u8e2a\u5df2\u9881\u53d1\u7684\u8bc1\u4e66\u3002\nnew_certs_dir\uff1a\u65b0\u8bc1\u4e66\u7684\u9ed8\u8ba4\u5b58\u50a8\u4f4d\u7f6e\u3002\ncertificate\uff1aCA\u8bc1\u4e66\u7684\u4f4d\u7f6e\u3002\nserial\uff1a\u5f53\u524d\u7684\u5e8f\u5217\u53f7\u6587\u4ef6\u7684\u4f4d\u7f6e\u3002\u6b64\u6587\u4ef6\u5305\u542b\u4e86\u4e0b\u4e00\u4e2a\u5c06\u8981\u88ab\u9881\u53d1\u7684\u8bc1\u4e66\u7684\u5e8f\u5217\u53f7\u3002\ncrlnumber\uff1a\u5f53\u524d\u7684CRL\u7f16\u53f7\u7684\u4f4d\u7f6e\u3002\ncrl\uff1a\u5f53\u524d\u7684CRL\u7684\u4f4d\u7f6e\u3002\nprivate_key\uff1a\u79c1\u94a5\u7684\u4f4d\u7f6e\u3002\nx509_extensions\uff1a\u6dfb\u52a0\u5230\u8bc1\u4e66\u4e2d\u7684X.509\u6269\u5c55\u3002\nname_opt \u548c cert_opt\uff1a\u5b9a\u4e49\u4e86\u8bc1\u4e66\u4e2d\u4e3b\u9898\u540d\u79f0\u548c\u8bc1\u4e66\u5b57\u6bb5\u7684\u9009\u9879\u3002\ndefault_days\uff1a\u8bc1\u4e66\u7684\u9ed8\u8ba4\u6709\u6548\u671f\uff08\u5929\u6570\uff09\u3002\ndefault_crl_days\uff1a\u4e0b\u4e00\u4e2aCRL\u4e4b\u524d\u7684\u9ed8\u8ba4\u5929\u6570\u3002\ndefault_md\uff1a\u9ed8\u8ba4\u4f7f\u7528\u7684\u6d88\u606f\u6458\u8981\u7b97\u6cd5\u3002\npreserve\uff1a\u662f\u5426\u4fdd\u7559\u4f20\u9012\u7684DN\u6392\u5e8f\u3002\n#\u7136\u540e\u6709\u4e00\u4e2a\u540d\u4e3a policy_match \u7684\u90e8\u5206\uff0c\u8fd9\u662f\u4e00\u4e2a\u7b56\u7565\u6bb5\uff0c\u5b83\u5b9a\u4e49\u4e86\u5728\u8bc1\u4e66\u7533\u8bf7\u65f6\u9700\u8981\u5339\u914d\u6216\u4f9b\u5e94\u7684\u5b57\u6bb5\u3002\ncountryName\u3001stateOrProvinceName\u3001organizationName\uff1a\u5728\u8bc1\u4e66\u7533\u8bf7\u4e2d\u5fc5\u987b\u5339\u914d\u7684\u5b57\u6bb5\u3002\norganizationalUnitName\u3001emailAddress\uff1a\u53ef\u9009\u5b57\u6bb5\u3002\ncommonName\uff1a\u5fc5\u987b\u5728\u8bc1\u4e66\u7533\u8bf7\u4e2d\u63d0\u4f9b\u7684\u5b57\u6bb5<\/code><\/pre>\n<h2>2.\u7279\u6709\u540d\u8bcd\u4ecb\u7ecd<\/h2>\n<pre><code class=\"language-bash\">CSR\uff08\u8bc1\u4e66\u7b7e\u540d\u8bf7\u6c42 Certificate Signing Request\uff09\uff1aCSR\u662f\u4e00\u79cd\u6570\u636e\u6587\u4ef6\uff0c\u7528\u4e8e\u5411\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u8bf7\u6c42\u6570\u5b57\u8bc1\u4e66\u3002\u5f53\u4f60\u5e0c\u671b\u5728\u670d\u52a1\u5668\u4e0a\u542f\u7528SSL\/TLS\u52a0\u5bc6\u8fde\u63a5\u65f6\uff0c\u4f60\u9700\u8981\u751f\u6210\u4e00\u4e2aCSR\u6587\u4ef6\u5e76\u5c06\u5176\u53d1\u9001\u7ed9CA\u3002CSR\u5305\u542b\u4e86\u4e0e\u8bc1\u4e66\u76f8\u5173\u7684\u4fe1\u606f\uff0c\u5982\u516c\u94a5\u3001\u7ec4\u7ec7\u540d\u79f0\u7b49\u3002CA\u4f7f\u7528CSR\u6765\u9a8c\u8bc1\u4f60\u7684\u8eab\u4efd\uff0c\u5e76\u4e3a\u4f60\u7b7e\u53d1\u76f8\u5e94\u7684\u6570\u5b57\u8bc1\u4e66\u3002\u5728\u516c\u94a5\u57fa\u7840\u8bbe\u65af\uff08PKI\uff09\u4e2d\uff0cCSR\u662f\u7531\u8bc1\u4e66\u7533\u8bf7\u8005\u751f\u6210\u7684\u6587\u4ef6\uff0c\u7528\u4e8e\u5411\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u8bf7\u6c42\u7b7e\u53d1\u6570\u5b57\u8bc1\u4e66\u3002\nSR\u5305\u542b\u4e86\u4e00\u4e9b\u5173\u952e\u7684\u4fe1\u606f\uff0c\u5305\u62ec\uff1a\n1.\u516c\u94a5\uff1aCSR\u4e2d\u5305\u542b\u4e86\u8bc1\u4e66\u7533\u8bf7\u8005\u7684\u516c\u94a5\u3002\u8be5\u516c\u94a5\u5c06\u5305\u542b\u5728\u6700\u7ec8\u7b7e\u53d1\u7684\u6570\u5b57\u8bc1\u4e66\u4e2d\uff0c\u7528\u4e8e\u52a0\u5bc6\u548c\u8eab\u4efd\u9a8c\u8bc1\u3002\n2.\u4e3b\u9898\u4fe1\u606f\uff1aCSR\u4e2d\u5305\u542b\u4e86\u8bc1\u4e66\u7533\u8bf7\u8005\u7684\u8eab\u4efd\u4fe1\u606f\uff0c\u5982\u540d\u79f0\u3001\u7ec4\u7ec7\u5355\u4f4d\u3001\u56fd\u5bb6\/\u5730\u533a\u7b49\u3002\u8fd9\u4e9b\u4fe1\u606f\u5c06\u51fa\u73b0\u5728\u6700\u7ec8\u7b7e\u53d1\u7684\u6570\u5b57\u8bc1\u4e66\u4e2d\uff0c\u7528\u4e8e\u8bc1\u4e66\u7684\u8bc6\u522b\u548c\u8eab\u4efd\u9a8c\u8bc1\u3002\n3.\u6269\u5c55\u4fe1\u606f\uff1aCSR\u53ef\u4ee5\u5305\u542b\u5176\u4ed6\u6269\u5c55\u4fe1\u606f\uff0c\u5982\u4e3b\u4f53\u5907\u7528\u540d\u79f0\uff08SANs\uff09\u3001\u5bc6\u94a5\u7528\u9014\u3001\u5bc6\u94a5\u7528\u6cd5\u9650\u5236\u7b49\u3002\n\u751f\u6210CSR\u7684\u8fc7\u7a0b\u4e00\u822c\u662f\u8fd9\u6837\u7684\uff1a\n1.\u751f\u6210\u5bc6\u94a5\u5bf9\uff1a\u8bc1\u4e66\u7533\u8bf7\u8005\u9996\u5148\u751f\u6210\u4e00\u5bf9\u5bc6\u94a5\uff1a\u516c\u94a5\u548c\u79c1\u94a5\u3002\u79c1\u94a5\u7528\u4e8e\u52a0\u5bc6\u548c\u89e3\u5bc6\u6570\u636e\uff0c\u516c\u94a5\u7528\u4e8e\u9a8c\u8bc1\u7b7e\u540d\u548c\u52a0\u5bc6\u6570\u636e\u3002\n2.\u521b\u5efaCSR\uff1a\u4f7f\u7528\u751f\u6210\u7684\u5bc6\u94a5\u5bf9\uff0c\u8bc1\u4e66\u7533\u8bf7\u8005\u751f\u6210\u5305\u542b\u6240\u9700\u4fe1\u606f\u7684CSR\u6587\u4ef6\u3002\u8fd9\u901a\u5e38\u901a\u8fc7\u4f7f\u7528\u8bc1\u4e66\u7ba1\u7406\u5de5\u5177\uff08\u5982OpenSSL\uff09\u6765\u5b8c\u6210\u3002\n3.\u63d0\u4ea4CSR\uff1a\u5c06\u751f\u6210\u7684CSR\u6587\u4ef6\u63d0\u4ea4\u7ed9CA\uff0c\u8bf7\u6c42\u7b7e\u53d1\u6570\u5b57\u8bc1\u4e66\u3002CA\u5c06\u9a8c\u8bc1CSR\u4e2d\u7684\u4fe1\u606f\uff0c\u7136\u540e\u6839\u636e\u9a8c\u8bc1\u7ed3\u679c\u7b7e\u53d1\u76f8\u5e94\u7684\u6570\u5b57\u8bc1\u4e66\u3002\nCSR\u662f\u7533\u8bf7\u8005\u4e0eCA\u4e4b\u95f4\u7684\u901a\u4fe1\u5a92\u4ecb\u3002\u5b83\u5305\u542b\u4e86\u7533\u8bf7\u8005\u7684\u516c\u94a5\u548c\u8eab\u4efd\u4fe1\u606f\uff0c\u4e3aCA\u63d0\u4f9b\u4e86\u751f\u6210\u76f8\u5e94\u6570\u5b57\u8bc1\u4e66\u6240\u9700\u7684\u4fe1\u606f\u3002\u901a\u8fc7CSR\uff0c\u8bc1\u4e66\u7533\u8bf7\u8005\u53ef\u4ee5\u8bf7\u6c42CA\u4e3a\u5176\u751f\u6210\u5408\u9002\u7684\u6570\u5b57\u8bc1\u4e66\uff0c\u7528\u4e8e\u52a0\u5bc6\u901a\u4fe1\u3001\u8eab\u4efd\u9a8c\u8bc1\u548c\u6570\u636e\u5b8c\u6574\u6027\u4fdd\u62a4\u7b49\u76ee\u7684\u3002\n\nCRL\uff08\u8bc1\u4e66\u64a4\u9500\u5217\u8868 Certificate Revocation List\uff09\uff1aCRL\u662f\u4e00\u4e2a\u5305\u542b\u5df2\u7ecf\u88ab\u64a4\u9500\u7684\u8bc1\u4e66\u5217\u8868\u7684\u6587\u4ef6\u3002\u5f53\u4e00\u4e2a\u6570\u5b57\u8bc1\u4e66\u7684\u79c1\u94a5\u6cc4\u9732\u3001\u8bc1\u4e66\u8fc7\u671f\u6216\u6301\u6709\u8005\u7684\u8eab\u4efd\u4fe1\u606f\u53d1\u751f\u53d8\u5316\u7b49\u60c5\u51b5\u4e0b\uff0c\u8bc1\u4e66\u9700\u8981\u88ab\u64a4\u9500\u3002CA\u4f1a\u5c06\u8fd9\u4e9b\u88ab\u64a4\u9500\u7684\u8bc1\u4e66\u4fe1\u606f\u53d1\u5e03\u5230CRL\u4e2d\uff0c\u4ee5\u4fbf\u7528\u6237\u80fd\u591f\u9a8c\u8bc1\u8bc1\u4e66\u7684\u6709\u6548\u6027\u3002\u5ba2\u6237\u7aef\u5728\u5efa\u7acbSSL\/TLS\u8fde\u63a5\u65f6\uff0c\u4f1a\u68c0\u67e5\u8bc1\u4e66\u662f\u5426\u5b58\u5728\u4e8eCRL\u4e2d\uff0c\u4ee5\u786e\u4fdd\u8bc1\u4e66\u7684\u5408\u6cd5\u6027\u3002\u5728\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\uff08PKI\uff09\u4e2d\uff0cCRL\u662f\u7531\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u53d1\u5e03\u7684\u5305\u542b\u5df2\u64a4\u9500\u8bc1\u4e66\u4fe1\u606f\u7684\u5217\u8868\nCRL\u7684\u4e3b\u8981\u4f5c\u7528\u662f\u901a\u77e5\u7cfb\u7edf\u548c\u5b9e\u4f53\u67d0\u4e9b\u6570\u5b57\u8bc1\u4e66\u5df2\u7ecf\u88ab\u64a4\u9500\uff0c\u4e0d\u518d\u53ef\u4fe1\u3002\u8bc1\u4e66\u53ef\u80fd\u4f1a\u88ab\u64a4\u9500\u7684\u539f\u56e0\u5305\u62ec\u79c1\u94a5\u6cc4\u9732\u3001\u8bc1\u4e66\u8fc7\u671f\u3001\u6301\u6709\u8005\u8eab\u4efd\u53d8\u66f4\u7b49\u3002\u901a\u8fc7\u67e5\u770bCRL\uff0c\u53ef\u4ee5\u786e\u8ba4\u8bc1\u4e66\u7684\u6709\u6548\u6027\u548c\u64a4\u9500\u72b6\u6001\u3002\nCRL\u901a\u5e38\u662f\u4ee5\u6587\u4ef6\u5f62\u5f0f\u53d1\u5e03\uff0c\u5176\u4e2d\u5305\u542b\u5df2\u64a4\u9500\u8bc1\u4e66\u7684\u5e8f\u5217\u53f7\u3001\u64a4\u9500\u65e5\u671f\u548c\u64a4\u9500\u539f\u56e0\u7b49\u4fe1\u606f\u3002\u5e94\u7528\u7a0b\u5e8f\u548c\u7cfb\u7edf\u53ef\u4ee5\u4f7f\u7528CRL\u6765\u9a8c\u8bc1\u8bc1\u4e66\u7684\u72b6\u6001\uff0c\u5373\u68c0\u67e5\u8bc1\u4e66\u662f\u5426\u5b58\u5728\u4e8eCRL\u4e2d\uff0c\u5982\u679c\u662f\uff0c\u5219\u8bc1\u4e66\u88ab\u8ba4\u4e3a\u662f\u64a4\u9500\n\u4e00\u4e9b\u5e38\u89c1\u7684\u64cd\u4f5c\u5305\u62ec\uff1a\n1.\u8bc1\u4e66\u9a8c\u8bc1\uff1a\u5f53\u4f7f\u7528\u8bc1\u4e66\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1\u6216\u5b89\u5168\u901a\u4fe1\u65f6\uff0c\u7cfb\u7edf\u53ef\u4ee5\u68c0\u67e5\u8be5\u8bc1\u4e66\u662f\u5426\u5b58\u5728\u4e8eCRL\u4e2d\uff0c\u4ee5\u786e\u8ba4\u8bc1\u4e66\u7684\u72b6\u6001\u548c\u6709\u6548\u6027\u3002\n2.\u81ea\u52a8\u66f4\u65b0\uff1a\u7cfb\u7edf\u53ef\u4ee5\u5468\u671f\u6027\u5730\u4e0b\u8f7d\u6700\u65b0\u7684CRL\uff0c\u5e76\u81ea\u52a8\u66f4\u65b0\u672c\u5730\u7684\u64a4\u9500\u5217\u8868\uff0c\u4ee5\u786e\u4fdd\u4f7f\u7528\u6700\u65b0\u7684\u4fe1\u606f\u6765\u9a8c\u8bc1\u8bc1\u4e66\u3002\n3.OCSP\uff1a\u9664\u4e86\u4f7f\u7528CRL\u5916\uff0c\u7cfb\u7edf\u8fd8\u53ef\u4ee5\u901a\u8fc7\u5728\u7ebf\u8bc1\u4e66\u72b6\u6001\u534f\u8bae\uff08OCSP\uff09\u5411CA\u67e5\u8be2\u7279\u5b9a\u8bc1\u4e66\u7684\u72b6\u6001\u3002OCSP\u63d0\u4f9b\u4e86\u5b9e\u65f6\u7684\u8bc1\u4e66\u72b6\u6001\u67e5\u8be2\uff0c\u76f8\u5bf9\u4e8eCRL\u66f4\u65b0\u5468\u671f\u53ef\u80fd\u66f4\u5b9e\u65f6\u548c\u9ad8\u6548\u3002\n\u901a\u8fc7\u4f7f\u7528CRL\uff0cPKI\u7cfb\u7edf\u53ef\u4ee5\u53ca\u65f6\u5730\u901a\u77e5\u5404\u65b9\u7279\u5b9a\u8bc1\u4e66\u7684\u64a4\u9500\u72b6\u6001\uff0c\u4ece\u800c\u786e\u4fdd\u7cfb\u7edf\u4e2d\u7684\u8bc1\u4e66\u94fe\u662f\u53ef\u4fe1\u7684\u3002CRL\u662fPKI\u4e2d\u7684\u4e00\u4e2a\u91cd\u8981\u7ec4\u4ef6\uff0c\u7528\u4e8e\u7ef4\u62a4\u8bc1\u4e66\u7684\u53ef\u4fe1\u6027\u548c\u5b89\u5168\u6027\u3002\n\nCA\u4ee3\u8868\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08Certificate Authority\uff09\u3002CA\u662f\u4e00\u79cd\u53ef\u4fe1\u4efb\u7684\u5b9e\u4f53\uff0c\u8d1f\u8d23\u9a8c\u8bc1\u548c\u7b7e\u53d1\u6570\u5b57\u8bc1\u4e66\uff0c\u7528\u4e8e\u52a0\u5bc6\u901a\u4fe1\u548c\u8eab\u4efd\u9a8c\u8bc1\u3002\u4f5c\u4e3a\u4e00\u4e2aCA\uff0c\u5728\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\uff08PKI\uff09\u4e2d\u626e\u6f14\u7740\u5173\u952e\u7684\u89d2\u8272\u3002\u5b83\u8d1f\u8d23\u751f\u6210\u548c\u7b7e\u7f72\u6570\u5b57\u8bc1\u4e66\uff0c\u8bc1\u5b9e\u516c\u94a5\u4e0e\u5b9e\u4f53\uff08\u4f8b\u5982\u7f51\u7ad9\u3001\u7ec4\u7ec7\u6216\u4e2a\u4eba\uff09\u7684\u8eab\u4efd\u4e4b\u95f4\u7684\u5173\u8054\u3002Linux\u4e2d\u7684CA\u53ef\u4ee5\u662f\u4e00\u4e2a\u7b2c\u4e09\u65b9\u673a\u6784\uff08\u5982\u5168\u7403\u6027\u7684CA\uff0c\u5982VeriSign\u3001Let&#039;s Encrypt\u7b49\uff09\uff0c\u4e5f\u53ef\u4ee5\u662f\u81ea\u5df1\u5185\u90e8\u7ec4\u7ec7\u521b\u5efa\u7684\u79c1\u6709CA\u3002\n\u4e00\u4e2aCA\u901a\u5e38\u6709\u4ee5\u4e0b\u529f\u80fd\uff1a\n1.\u8bc1\u4e66\u7b7e\u53d1\uff1aCA\u6839\u636e\u9a8c\u8bc1\u7684\u8eab\u4efd\u4fe1\u606f\u751f\u6210\u548c\u7b7e\u53d1\u6570\u5b57\u8bc1\u4e66\u3002\u8fd9\u4e9b\u6570\u5b57\u8bc1\u4e66\u5305\u542b\u4e86\u5b9e\u4f53\u7684\u516c\u94a5\u3001\u8eab\u4efd\u4fe1\u606f\u548c\u5176\u4ed6\u76f8\u5173\u4fe1\u606f\u3002\n2.\u8bc1\u4e66\u9a8c\u8bc1\uff1aCA\u8d1f\u8d23\u9a8c\u8bc1\u63a5\u6536\u5230\u7684\u8bc1\u4e66\u7684\u5408\u6cd5\u6027\u3002\u5b83\u4f1a\u68c0\u67e5\u8bc1\u4e66\u7684\u7b7e\u540d\u662f\u5426\u6709\u6548\u3001\u8bc1\u4e66\u662f\u5426\u5728\u6709\u6548\u671f\u5185\uff0c\u5e76\u4e0eCA\u7684\u8bc1\u4e66\u8fdb\u884c\u5bf9\u6bd4\u4ee5\u786e\u8ba4\u5176\u5408\u6cd5\u6027\u3002\n3.\u8bc1\u4e66\u64a4\u9500\uff1a\u5f53\u6570\u5b57\u8bc1\u4e66\u7684\u79c1\u94a5\u6cc4\u9732\u3001\u8bc1\u4e66\u8fc7\u671f\u6216\u6301\u6709\u8005\u7684\u8eab\u4efd\u4fe1\u606f\u53d1\u751f\u53d8\u5316\u7b49\u60c5\u51b5\u4e0b\uff0cCA\u4f1a\u64a4\u9500\u76f8\u5e94\u7684\u8bc1\u4e66\u3002\u5b83\u4f1a\u751f\u6210\u8bc1\u4e66\u64a4\u9500\u5217\u8868\uff08CRL\uff09\u6216\u4f7f\u7528\u5728\u7ebf\u8bc1\u4e66\u72b6\u60014\u534f\u8bae\uff08OCSP\uff09\u6765\u516c\u5f00\u5df2\u64a4\u9500\u7684\u8bc1\u4e66\u4fe1\u606f\u3002\n4.\u5bc6\u94a5\u7ba1\u7406\uff1aCA\u8d1f\u8d23\u751f\u6210\u3001\u5b58\u50a8\u548c\u4fdd\u62a4\u7528\u4e8e\u7b7e\u7f72\u8bc1\u4e66\u7684\u79c1\u94a5\u3002\u79c1\u94a5\u7684\u5b89\u5168\u6027\u5bf9\u4e8e\u786e\u4fdd\u8bc1\u4e66\u7684\u53ef\u4fe1\u6027\u81f3\u5173\u91cd\u8981\u3002\n\nPKI\u4ee3\u8868\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\uff08Public Key Infrastructure\uff09\u3002PKI\u662f\u4e00\u79cd\u7cfb\u7edf\u548c\u6846\u67b6\uff0c\u7528\u4e8e\u7ba1\u7406\u548c\u63d0\u4f9b\u52a0\u5bc6\u3001\u8eab\u4efd\u9a8c\u8bc1\u548c\u6570\u636e\u5b8c\u6574\u6027\u7b49\u5b89\u5168\u670d\u52a1\u3002\u5b83\u4f7f\u7528\u516c\u94a5\u5bc6\u7801\u5b66\u6765\u5b9e\u73b0\u8fd9\u4e9b\u5b89\u5168\u670d\u52a1\u3002\n\u5728PKI\u4e2d\uff0c\u6709\u4ee5\u4e0b\u4e3b\u8981\u7ec4\u4ef6\uff1a\n1.\u516c\u94a5\u548c\u79c1\u94a5\uff1aPKI\u4f7f\u7528\u975e\u5bf9\u79f0\u52a0\u5bc6\u7b97\u6cd5\uff0c\u5176\u4e2d\u5305\u62ec\u4e00\u5bf9\u5bc6\u94a5\uff1a\u516c\u94a5\u548c\u79c1\u94a5\u3002\u516c\u94a5\u7528\u4e8e\u52a0\u5bc6\u6570\u636e\u6216\u9a8c\u8bc1\u7b7e\u540d\uff0c\u800c\u79c1\u94a5\u7528\u4e8e\u89e3\u5bc6\u6570\u636e\u6216\u751f\u6210\u7b7e\u540d\u3002\u516c\u94a5\u662f\u516c\u5f00\u7684\uff0c\u800c\u79c1\u94a5\u662f\u4fdd\u5bc6\u7684\u3002\n2.\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\uff1aCA\u662f\u8d1f\u8d23\u9a8c\u8bc1\u5b9e\u4f53\u8eab\u4efd\u5e76\u7b7e\u53d1\u6570\u5b57\u8bc1\u4e66\u7684\u53ef\u4fe1\u4efb\u673a\u6784\u3002\u5b83\u751f\u6210\u5305\u542b\u516c\u94a5\u548c\u5b9e\u4f53\u8eab\u4efd\u4fe1\u606f\u7684\u6570\u5b57\u8bc1\u4e66\uff0c\u5e76\u4f7f\u7528\u81ea\u5df1\u7684\u79c1\u94a5\u5bf9\u8bc1\u4e66\u8fdb\u884c\u7b7e\u540d\u3002CA\u901a\u8fc7\u7b7e\u540d\u8bc1\u4e66\u6765\u786e\u4fdd\u8bc1\u4e66\u7684\u771f\u5b9e\u6027\u548c\u5b8c\u6574\u6027\u3002\n3.\u6570\u5b57\u8bc1\u4e66\uff1a\u6570\u5b57\u8bc1\u4e66\u662f\u5305\u542b\u516c\u94a5\u3001\u5b9e\u4f53\u8eab\u4efd\u4fe1\u606f\u548cCA\u7b7e\u540d\u7684\u6570\u636e\u6587\u4ef6\u3002\u5b83\u7528\u4e8e\u9a8c\u8bc1\u5b9e\u4f53\u8eab\u4efd\u548c\u8fdb\u884c\u5b89\u5168\u901a\u4fe1\u3002\u8bc1\u4e66\u4e2d\u7684CA\u7b7e\u540d\u53ef\u4ee5\u7528\u6765\u9a8c\u8bc1\u8bc1\u4e66\u7684\u5408\u6cd5\u6027\uff0c\u786e\u4fdd\u8bc1\u4e66\u672a\u88ab\u7be1\u6539\u3002\n4.\u8bc1\u4e66\u64a4\u9500\u5217\u8868\uff08CRL\uff09\uff1aCRL\u662f\u7531CA\u53d1\u5e03\u7684\u5305\u542b\u5df2\u64a4\u9500\u8bc1\u4e66\u5217\u8868\u7684\u6587\u4ef6\u3002\u5f53\u8bc1\u4e66\u9700\u8981\u88ab\u64a4\u9500\uff08\u5982\u79c1\u94a5\u6cc4\u9732\u3001\u8bc1\u4e66\u8fc7\u671f\u7b49\uff09\u65f6\uff0cCA\u4f1a\u5c06\u76f8\u5e94\u7684\u8bc1\u4e66\u4fe1\u606f\u6dfb\u52a0\u5230CRL\u4e2d\uff0c\u4ee5\u4fbf\u5176\u4ed6\u4eba\u53ef\u4ee5\u9a8c\u8bc1\u8bc1\u4e66\u7684\u72b6\u6001\u3002\n5.\u6ce8\u518c\u673a\u6784\uff08RA\uff09\uff1aRA\u662fCA\u7684\u8f85\u52a9\u673a\u6784\uff0c\u8d1f\u8d23\u5904\u7406\u8bc1\u4e66\u8bf7\u6c42\u3001\u9a8c\u8bc1\u7528\u6237\u8eab\u4efd\u7b49\u64cd\u4f5c\u3002\u5b83\u4e0e\u7528\u6237\u76f4\u63a5\u4ea4\u4e92\uff0c\u5e76\u5c06\u9a8c\u8bc1\u7684\u8bc1\u4e66\u8bf7\u6c42\u4f20\u9012\u7ed9CA\u8fdb\u884c\u7b7e\u53d1\u3002\nPKI\u63d0\u4f9b\u4e86\u4e00\u79cd\u53ef\u9760\u7684\u673a\u5236\u6765\u5efa\u7acb\u4fe1\u4efb\u3001\u52a0\u5bc6\u901a\u4fe1\u548c\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1\u3002\u5b83\u88ab\u5e7f\u6cdb\u7528\u4e8e\u5b89\u5168\u901a\u4fe1\u534f\u8bae\uff08\u5982SSL\/TLS\uff09\u3001\u6570\u5b57\u7b7e\u540d\u3001\u8eab\u4efd\u9a8c\u8bc1\u3001VPN\u7b49\u573a\u666f\u4e2d\uff0c\u786e\u4fdd\u6570\u636e\u7684\u673a\u5bc6\u6027\u3001\u5b8c\u6574\u6027\u548c\u8eab\u4efd\u7684\u771f\u5b9e\u6027\u3002\n\nRA\u4ee3\u8868\u6ce8\u518c\u673a\u6784\uff08Registration Authority\uff09\u3002\u5728\u516c\u94a5\u57fa\u7840\u8bbe\u65bd\uff08PKI\uff09\u4e2d\uff0cRA\u662f\u4e00\u4e2a\u8f85\u52a9\u673a\u6784\uff0c\u8d1f\u8d23\u5904\u7406\u8bc1\u4e66\u8bf7\u6c42\u548c\u9a8c\u8bc1\u7528\u6237\u8eab\u4efd\u7b49\u64cd\u4f5c\u3002\nRA\u5728PKI\u4e2d\u7684\u89d2\u8272\u5305\u62ec\uff1a\n1.\u7528\u6237\u8eab\u4efd\u9a8c\u8bc1\uff1aRA\u8d1f\u8d23\u9a8c\u8bc1\u7528\u6237\u7684\u8eab\u4efd\u3002\u5b83\u53ef\u4ee5\u8981\u6c42\u7528\u6237\u63d0\u4f9b\u76f8\u5173\u8eab\u4efd\u8bc1\u660e\u6750\u6599\uff0c\u5e76\u6267\u884c\u9002\u5f53\u7684\u8eab\u4efd\u9a8c\u8bc1\u6d41\u7a0b\uff0c\u4ee5\u786e\u4fdd\u7528\u6237\u5177\u6709\u5408\u6cd5\u7684\u8eab\u4efd\u3002\n2.\u8bc1\u4e66\u8bf7\u6c42\u5904\u7406\uff1aRA\u63a5\u6536\u5e76\u5904\u7406\u6765\u81ea\u7528\u6237\u7684\u8bc1\u4e66\u8bf7\u6c42\u3002\u5b83\u4f1a\u9a8c\u8bc1\u8bc1\u4e66\u8bf7\u6c42\u7684\u5b8c\u6574\u6027\u548c\u51c6\u786e\u6027\uff0c\u5e76\u4e0e\u76f8\u5173\u7684\u8eab\u4efd\u9a8c\u8bc1\u4fe1\u606f\u8fdb\u884c\u5339\u914d\u3002\n3.\u8bc1\u4e66\u8bf7\u6c42\u4f20\u9012\u7ed9CA\uff1aRA\u5c06\u7ecf\u8fc7\u9a8c\u8bc1\u7684\u8bc1\u4e66\u8bf7\u6c42\u4f20\u9012\u7ed9\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u3002CA\u4f7f\u7528RA\u63d0\u4f9b\u7684\u9a8c\u8bc1\u7ed3\u679c\u6765\u51b3\u5b9a\u662f\u5426\u7b7e\u53d1\u76f8\u5e94\u7684\u6570\u5b57\u8bc1\u4e66\u3002\n4.\u5bc6\u94a5\u751f\u6210\u548c\u5206\u53d1\uff1a\u5728\u4e00\u4e9b\u60c5\u51b5\u4e0b\uff0cRA\u53ef\u80fd\u8d1f\u8d23\u751f\u6210\u7528\u6237\u5bc6\u94a5\u5bf9\uff0c\u5e76\u5c06\u516c\u94a5\u548c\u76f8\u5173\u8bc1\u4e66\u5206\u53d1\u7ed9\u7528\u6237\u3002\u8fd9\u786e\u4fdd\u4e86\u5bc6\u94a5\u751f\u6210\u7684\u5b89\u5168\u6027\u548c\u53ef\u4fe1\u5ea6\u3002\n5.\u8bc1\u4e66\u751f\u547d\u5468\u671f\u7ba1\u7406\uff1aRA\u53ef\u80fd\u53c2\u4e0e\u8bc1\u4e66\u7684\u751f\u547d\u5468\u671f\u7ba1\u7406\u3002\u5b83\u53ef\u4ee5\u5e2e\u52a9\u7528\u6237\u8fdb\u884c\u8bc1\u4e66\u66f4\u65b0\u3001\u8bc1\u4e66\u540a\u9500\u548c\u8bc1\u4e66\u66f4\u65b0\u7b49\u64cd\u4f5c\uff0c\u5e76\u4e0eCA\u8fdb\u884c\u534f\u8c03\u3002\n\u603b\u4f53\u800c\u8a00\uff0cRA\u5728PKI\u4e2d\u8d77\u7740\u8fde\u63a5\u7528\u6237\u548cCA\u4e4b\u95f4\u7684\u6865\u6881\u4f5c\u7528\u3002\u5b83\u5e2e\u52a9\u786e\u4fdd\u8bc1\u4e66\u8bf7\u6c42\u7684\u5408\u6cd5\u6027\u548c\u7528\u6237\u8eab\u4efd\u7684\u771f\u5b9e\u6027\uff0c\u5e76\u5c06\u9a8c\u8bc1\u901a\u8fc7\u7684\u8bf7\u6c42\u4f20\u9012\u7ed9CA\u8fdb\u884c\u8bc1\u4e66\u7b7e\u53d1\u3002RA\u7684\u5b58\u5728\u7b80\u5316\u4e86\u8bc1\u4e66\u7b7e\u53d1\u8fc7\u7a0b\uff0c\u5e76\u589e\u52a0\u4e86\u5bf9\u7528\u6237\u8eab\u4efd\u9a8c\u8bc1\u7684\u53ef\u9760\u6027\u3002\n\n.pem&quot; \u662f\u4e00\u79cd\u5e38\u89c1\u7684\u6587\u4ef6\u6269\u5c55\u540d\uff0c\u5b83\u4ee3\u8868\u4e86\u9690\u79c1\u589e\u5f3a\u7535\u5b50\u90ae\u4ef6\uff08Privacy Enhanced Mail\uff09\u7684\u7f29\u5199\u3002\u5728\u5bc6\u7801\u5b66\u548c\u7f51\u7edc\u5b89\u5168\u4e2d\uff0c&quot;.pem&quot; \u6587\u4ef6\u901a\u5e38\u7528\u4e8e\u5b58\u50a8\u548c\u4f20\u8f93\u5bc6\u94a5\u3001\u8bc1\u4e66\u548c\u5176\u4ed6\u52a0\u5bc6\u76f8\u5173\u7684\u6570\u636e\u3002\nPEM \u683c\u5f0f\u662f\u4e00\u79cd\u57fa\u4e8e Base64 \u7f16\u7801\u7684\u6587\u672c\u683c\u5f0f\uff0c\u7528\u4e8e\u8868\u793a\u5bc6\u94a5\u3001\u8bc1\u4e66\u548c\u5176\u4ed6\u5b89\u5168\u76f8\u5173\u7684\u6570\u636e\u3002\u8fd9\u79cd\u683c\u5f0f\u7684\u6587\u4ef6\u901a\u5e38\u4ee5 &quot;.pem&quot; \u4f5c\u4e3a\u6587\u4ef6\u6269\u5c55\u540d\uff0c\u4f46\u5b9e\u9645\u4e0a\u6587\u4ef6\u5185\u5bb9\u662f\u6587\u672c\u6570\u636e\uff0c\u53ef\u4ee5\u7528\u4efb\u4f55\u6587\u672c\u7f16\u8f91\u5668\u6253\u5f00\u67e5\u770b\u3002\n.pem \u6587\u4ef6\u53ef\u4ee5\u5305\u542b\u591a\u79cd\u7c7b\u578b\u7684\u6570\u636e\uff0c\u4f8b\u5982\uff1a\n\u79c1\u94a5\uff08Private Key\uff09\uff1aRSA\u3001DSA\u3001ECDSA \u7b49\u79c1\u94a5\u53ef\u4ee5\u4ee5 PEM \u683c\u5f0f\u5b58\u50a8\u5728 .pem \u6587\u4ef6\u4e2d\u3002\n\u516c\u94a5\uff08Public Key\uff09\uff1aRSA\u3001DSA\u3001ECDSA \u7b49\u516c\u94a5\u4e5f\u53ef\u4ee5\u4ee5 PEM \u683c\u5f0f\u5b58\u50a8\u5728 .pem \u6587\u4ef6\u4e2d\u3002\n\u8bc1\u4e66\uff08Certificate\uff09\uff1aX.509 \u683c\u5f0f\u7684\u6570\u5b57\u8bc1\u4e66\u901a\u5e38\u4ee5 PEM \u683c\u5f0f\u7f16\u7801\uff0c\u5e76\u4fdd\u5b58\u4e3a .pem \u6587\u4ef6\u3002\nCSR\uff08Certificate Signing Request\uff09\uff1a\u751f\u6210\u8bc1\u4e66\u7b7e\u540d\u8bf7\u6c42\u65f6\uff0c\u4e5f\u53ef\u4ee5\u5c06 CSR \u4ee5 PEM \u683c\u5f0f\u4fdd\u5b58\u5728 .pem \u6587\u4ef6\u4e2d\u3002\n\u5176\u4ed6\u52a0\u5bc6\u76f8\u5173\u7684\u6570\u636e\uff1aPEM \u683c\u5f0f\u8fd8\u53ef\u4ee5\u7528\u4e8e\u5b58\u50a8\u52a0\u5bc6\u7b97\u6cd5\u4e2d\u4f7f\u7528\u7684\u5176\u4ed6\u6570\u636e\uff0c\u5982\u53c2\u6570\u3001\u6563\u5217\u503c\u7b49\u3002\n\u603b\u4e4b\uff0c&quot;.pem&quot; \u662f\u4e00\u79cd\u6587\u4ef6\u6269\u5c55\u540d\uff0c\u7528\u4e8e\u6807\u8bc6\u5305\u542b\u52a0\u5bc6\u76f8\u5173\u6570\u636e\u7684\u6587\u672c\u6587\u4ef6\uff0c\u901a\u5e38\u4ee5 PEM \u683c\u5f0f\u8fdb\u884c\u7f16\u7801\u3002\n\n\u540e\u7f00\u540d\u4e3a &quot;.csr&quot; \u7684\u6587\u4ef6\u8868\u793a\u8bc1\u4e66\u7b7e\u540d\u8bf7\u6c42\uff08Certificate Signing Request\uff09\u3002CSR \u662f\u5728\u7533\u8bf7\u6570\u5b57\u8bc1\u4e66\u65f6\u751f\u6210\u7684\u6587\u4ef6\uff0c\u5176\u4e2d\u5305\u542b\u6709\u5173\u8bc1\u4e66\u8bf7\u6c42\u8005\uff08\u4f8b\u5982\u7f51\u7ad9\u6216\u7ec4\u7ec7\uff09\u7684\u4fe1\u606f\uff0c\u4ee5\u53ca\u8bf7\u6c42\u8005\u7684\u516c\u94a5\u3002\nCSR \u6587\u4ef6\u901a\u5e38\u662f\u4ee5 PEM \u683c\u5f0f\u7f16\u7801\u7684\u6587\u672c\u6587\u4ef6\u3002\u5b83\u5305\u542b\u4e86\u4e00\u6bb5\u52a0\u5bc6\u7b97\u6cd5\u751f\u6210\u7684\u516c\u94a5\u4ee5\u53ca\u4e0e\u4e4b\u5173\u8054\u7684\u8eab\u4efd\u4fe1\u606f\uff0c\u5982\u7ec4\u7ec7\u540d\u79f0\u3001\u57df\u540d\u7b49\u3002CSR \u6587\u4ef6\u5c06\u88ab\u53d1\u9001\u7ed9\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7528\u4e8e\u751f\u6210\u6570\u5b57\u8bc1\u4e66\u3002\n\u4f7f\u7528 OpenSSL \u5de5\u5177\u751f\u6210 CSR \u6587\u4ef6\u7684\u547d\u4ee4\u7c7b\u4f3c\u4e8e\u4ee5\u4e0b\u793a\u4f8b\uff1a\nopenssl req -new -key private_key.pem -out certificate.csr\n\u5176\u4e2d\uff0c&quot;private_key.pem&quot; \u662f\u79c1\u94a5\u6587\u4ef6\uff0c\u7528\u4e8e\u751f\u6210\u516c\u94a5\u548c\u4e0e\u4e4b\u5173\u8054\u7684 CSR\u3002\u6267\u884c\u6b64\u547d\u4ee4\u540e\uff0c\u5c06\u751f\u6210\u4e00\u4e2a\u540d\u4e3a &quot;certificate.csr&quot; \u7684\u6587\u4ef6\uff0c\u5176\u4e2d\u5305\u542b\u4e86 CSR \u7684\u4fe1\u606f\u3002\n\u8bf7\u6ce8\u610f\uff0cCSR \u6587\u4ef6\u4e0d\u5305\u542b\u79c1\u94a5\uff0c\u800c\u53ea\u5305\u542b\u516c\u94a5\u548c\u4e0e\u4e4b\u5173\u8054\u7684\u8eab\u4efd\u4fe1\u606f\u3002\u79c1\u94a5\u901a\u5e38\u7528\u4e8e\u5728\u751f\u6210 CSR \u540e\u5bf9\u6570\u636e\u8fdb\u884c\u7b7e\u540d\u548c\u52a0\u5bc6\u3002<\/code><\/pre>\n<h2>3.\u9881\u53d1\u8fc7\u7a0b<\/h2>\n<pre><code class=\"language-bash\">.\u642d\u5efa\u79c1\u6709CA\uff1a\u521b\u5efa\u79c1\u94a5\uff0c\u81ea\u7b7e\u540d\u8bc1\u4e66\n2.\u7ed9\u7528\u6237\u8fdb\u884c\u8bc1\u4e66\u7533\u8bf7\uff1a\u7528\u6237\u5148\u751f\u6210\u79c1\u94a5\uff0c\u7136\u540e\u901a\u8fc7\u751f\u6210\u79c1\u94a5\u7533\u8bf7\n\n\u751f\u6210\u79c1\u94a5\uff1aopenssl genrsa -out cakey.pem 2048\n\u751f\u6210CA\u81ea\u7b7e\u540d\u8bc1\u4e66\uff1aopenssl req -new -x509 -key \/etc\/pki\/CA\/private\/cakey.pem -days 3650 -out \/etc\/pki\/CA\/cacert.pem\n\u67e5\u770bCA\u81ea\u7b7e\u540d\u8bc1\u4e66\uff1aopenssl x509 -in \/etc\/pki\/CA\/cacret.pem -noout -text\n    \u67e5\u770b\u4f7f\u7528\u8005\uff1aopenssl x509 -in \/etc\/pki\/CA\/cacret.pem -noout -subject\n    \u67e5\u770b\u8bc1\u4e66\u7684\u6709\u6548\u671f\uff1aopenssl x509 -in \/etc\/pki\/CA\/cacret.pem -noout -dates\n\n\u7528\u6237\u751f\u6210\u79c1\u94a5\u6587\u4ef6\uff1aopenssl genrsa -out \/data\/app1\/app1.key 2048\nCSR\uff08\u8bc1\u4e66\u7b7e\u540d\u8bf7\u6c42 Certificate Signing Request\uff09\uff1aopenssl req -new -key \/data\/app1\/app1.key -out \/data\/app1\/app1.csr\ntouch \/etc\/pki\/CA\/index.txt\necho 01 &gt; \/etc\/pki\/CA\/serial\n\u9881\u53d1\u8bc1\u4e66\uff1aopenssl ca -in \/data\/app1\/app1.csr -out \/etc\/pki\/CA\/certs\/app1.crt -days 1000\n\u9a8c\u8bc1\u8bc1\u4e66\u6709\u6548\u6027\uff1aopenssl ca -status 01<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u5efa\u7acb\u79c1\u6709CA\u9881\u53d1\u8bc1\u4e66 1.\u793a\u4f8b\u6587\u4ef6\u4ecb\u7ecd #\u67e5\u770bOpenSSL\u8bc1\u4e66\u9881\u53d1\u673a\u6784(CA)\u7684\u914d\u7f6e\u6587\u4ef6\u7684\u793a\u4f8b\u6587\u4ef6 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[51],"tags":[52],"views":218,"_links":{"self":[{"href":"http:\/\/8.141.4.74\/index.php?rest_route=\/wp\/v2\/posts\/367"}],"collection":[{"href":"http:\/\/8.141.4.74\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/8.141.4.74\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/8.141.4.74\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/8.141.4.74\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=367"}],"version-history":[{"count":1,"href":"http:\/\/8.141.4.74\/index.php?rest_route=\/wp\/v2\/posts\/367\/revisions"}],"predecessor-version":[{"id":368,"href":"http:\/\/8.141.4.74\/index.php?rest_route=\/wp\/v2\/posts\/367\/revisions\/368"}],"wp:attachment":[{"href":"http:\/\/8.141.4.74\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/8.141.4.74\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=367"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/8.141.4.74\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}