城市直播房产教育博客汽车
投稿投诉
汽车报价
买车新车
博客专栏
专题精品
教育留学
高考读书
房产家居
彩票视频
直播黑猫
投资微博
城市上海
政务旅游

跟老韩学UbuntuServer2204cms帮助手册

11月3日 枯心人投稿
  跟老韩学LinuxSRE系列
  那些过往,如盛夏的月光,一如你青涩的脸庞。hanywhanyw:manopensslcmsgrepEv34;OPENSSLCMS(1SSL)OpenSSLOPENSSLCMS(1SSL)NAMEopensslcmsCMScommandSYNOPSISopensslcms〔help〕Generaloptions:〔infilename〕〔outfilename〕〔configconfigfile〕Operationoptions:〔encrypt〕〔decrypt〕〔sign〕〔verify〕〔resign〕〔signreceipt〕〔verifyreceiptreceipt〕〔digestcreate〕〔digestverify〕〔compress〕〔uncompress〕〔EncryptedDataencrypt〕〔EncryptedDatadecrypt〕〔datacreate〕〔dataout〕〔cmsout〕Fileformatoptions:〔informDERPEMSMIME〕〔outformDERPEMSMIME〕〔rctformDERPEMSMIME〕〔stream〕〔indef〕〔noindef〕〔binary〕〔crlfeol〕〔asciicrlf〕Keysandpasswordoptions:〔pwripasswordpassword〕〔secretkeykey〕〔secretkeyidid〕〔inkeyfilenameuri〕〔passinarg〕〔keyoptname:parameter〕〔keyformDERPEMP12ENGINE〕〔engineid〕〔providername〕〔providerpathpath〕〔propquerypropq〕〔randfiles〕〔writerandfile〕Encryptionoptions:〔originatorfile〕〔recipfile〕〔recipientcert。。。〕〔cipher〕〔wrapcipher〕〔aes128wrap〕〔aes192wrap〕〔aes256wrap〕〔des3wrap〕〔debugdecrypt〕Signingoptions:〔mddigest〕〔signerfile〕〔certfilefile〕〔cades〕〔nodetach〕〔nocerts〕〔noattr〕〔nosmimecap〕〔receiptrequestall〕〔receiptrequestfirst〕〔receiptrequestfromemailaddress〕〔receiptrequesttoemailaddress〕Verificationoptions:〔signerfile〕〔contentfilename〕〔nocontentverify〕〔noattrverify〕〔nosigs〕〔noverify〕〔nointern〕〔cades〕〔verifyretcode〕〔CAfilefile〕〔noCAfile〕〔CApathdir〕〔noCApath〕〔CAstoreuri〕〔noCAstore〕Outputoptions:〔keyid〕〔econtenttypetype〕〔text〕〔certsoutfile〕〔toaddr〕〔fromaddr〕〔subjectsubj〕Printingoptions:〔noout〕〔print〕〔nameoptoption〕〔receiptrequestprint〕Validationoptions:〔allowproxycerts〕〔attimetimestamp〕〔nochecktime〕〔checksssig〕〔crlcheck〕〔crlcheckall〕〔explicitpolicy〕〔extendedcrl〕〔ignorecritical〕〔inhibitany〕〔inhibitmap〕〔partialchain〕〔policyarg〕〔policycheck〕〔policyprint〕〔purposepurpose〕〔suiteB128〕〔suiteB128only〕〔suiteB192〕〔trustedfirst〕〔noaltchains〕〔usedeltas〕〔authlevelnum〕〔verifydepthnum〕〔verifyemailemail〕〔verifyhostnamehostname〕〔verifyipip〕〔verifynamename〕〔x509strict〕〔issuerchecks〕DESCRIPTIONThiscommandhandlesdatainCMSformatsuchasSMIMEv3。1emailmessages。Itcanencrypt,decrypt,sign,verify,compress,uncompress,andprintmessages。OPTIONSThereareanumberofoperationoptionsthatsetthetypeofoperationtobeperformed:encrypt,decrypt,sign,verify,resign,signreceipt,verifyreceipt,digestcreate,digestverify,compress,uncompress,EncryptedDataencrypt,EncryptedDatadecrypt,datacreate,dataout,orcmsout。Therelevanceoftheotheroptionsdependsontheoperationtypeandtheirmeaningmayvaryaccordingtoit。helpPrintoutausagemessage。GeneraloptionsinfilenameTheinputmessagetobeencryptedorsignedorthemessagetobedecryptedorverified。outfilenameThemessagetextthathasbeendecryptedorverifiedortheoutputMIMEformatmessagethathasbeensignedorverified。configconfigfileSeeConfigurationOptioninopenssl(1)。OperationoptionsencryptEncryptdataforthegivenrecipientcertificates。Inputfileisthemessagetobeencrypted。TheoutputfileistheencrypteddatainMIMEformat。TheactualCMStypeisEnvelopedData。Notethatnorevocationcheckisdonefortherecipientcert,soifthatkeyhasbeencompromised,othersmaybeabletodecryptthetext。decryptDecryptdatausingthesuppliedcertificateandprivatekey。ExpectsencrypteddatainMIMEformatfortheinputfile。Thedecrypteddataiswrittentotheoutputfile。signSigndatausingthesuppliedcertificateandprivatekey。Inputfileisthemessagetobesigned。ThesigneddatainMIMEformatiswrittentotheoutputfile。verifyVerifysigneddata。Expectsasigneddataoninputandoutputsthesigneddata。Bothcleartextandopaquesigningissupported。resignResignamessage:takeanexistingmessageandoneormorenewsigners。signreceiptGenerateandoutputasignedreceiptforthesuppliedmessage。Theinputmessagemustcontainasignedreceiptrequest。Functionalityisotherwisesimilartothesignoperation。verifyreceiptreceiptVerifyasignedreceiptinfilenamereceipt。Theinputmessagemustcontaintheoriginalreceiptrequest。Functionalityisotherwisesimilartotheverifyoperation。digestcreateCreateaCMSDigestedDatatype。digestverifyVerifyaCMSDigestedDatatypeandoutputthecontent。compressCreateaCMSCompressedDatatype。OpenSSLmustbecompiledwithzlibsupportforthisoptiontowork,otherwiseitwilloutputanerror。uncompressUncompressaCMSCompressedDatatypeandoutputthecontent。OpenSSLmustbecompiledwithzlibsupportforthisoptiontowork,otherwiseitwilloutputanerror。EncryptedDataencryptEncryptcontentusingsuppliedsymmetrickeyandalgorithmusingaCMSEncryptedDatatypeandoutputthecontent。EncryptedDatadecryptDecryptcontentusingsuppliedsymmetrickeyandalgorithmusingaCMSEncryptedDatatypeandoutputthecontent。datacreateCreateaCMSDatatype。dataoutDatatypeandoutputthecontent。cmsoutTakesaninputmessageandwritesoutaPEMencodedCMSstructure。FileformatoptionsinformDERPEMSMIMETheinputformatoftheCMSstructure(ifoneisbeingread);thedefaultisSMIME。Seeopensslformatoptions(1)fordetails。outformDERPEMSMIMETheoutputformatoftheCMSstructure(ifoneisbeingwritten);thedefaultisSMIME。Seeopensslformatoptions(1)fordetails。rctformDERPEMSMIMETthedefaultisSMIME。Seeopensslformatoptions(1)fordetails。stream,indefThestreamandindefoptionsareequivalentandenablestreamingIOforencodingoperations。Thispermitssinglepassprocessingofdatawithouttheneedtoholdtheentirecontentsinmemory,potentiallysupportingverylargefiles。StreamingisautomaticallysetforSMIMEsigningwithdetacheddataiftheoutputformatisSMIMEitiscurrentlyoffbydefaultforallotheroperations。noindefDisablestreamingIOwhereitwouldproduceandindefinitelengthconstructedencoding。Thisoptioncurrentlyhasnoeffect。Infuturestreamingwillbeenabledbydefaultonallrelevantoperationsandthisoptionwilldisableit。binaryNormallytheinputmessageisconvertedtocanonicalformatwhichiseffectivelyusingCRandLFasendofline:asrequiredbytheSMIMEspecification。Whenthisoptionispresentnotranslationoccurs。ThisisusefulwhenhandlingbinarydatawhichmaynotbeinMIMEformat。crlfeolNormallytheoutputfileusesasingleLFasendofline。WhenthisoptionispresentCRLFisusedinstead。asciicrlfWhensigninguseASCIICRLFformatcanonicalisation。Thisstripstrailingwhitespacefromalllines,deletestrailingblanklinesatEOFandsetstheencapsulatedcontenttype。ThisoptionisnormallyusedwithdetachedcontentandanoutputsignatureformatofDER。Thisoptionisnotnormallyneededwhenverifyingasitisenabledautomaticallyiftheencapsulatedcontentformatisdetected。KeysandpasswordoptionspwripasswordpasswordSpecifypasswordforrecipient。secretkeykeySpecifysymmetrickeytouse。Thekeymustbesuppliedinhexformatandbeconsistentwiththealgorithmused。SupportedbytheEncryptedDataencryptEncryptedDatadecrypt,encryptanddecryptoptions。WhenusedwithencryptordecryptthesuppliedkeyisusedtowraporunwrapthecontentencryptionkeyusinganAESkeyintheKEKRecipientInfotype。secretkeyididThekeyidentifierforthesuppliedsymmetrickeyforKEKRecipientInfotype。Thisoptionmustbepresentifthesecretkeyoptionisusedwithencrypt。WithdecryptoperationstheidisusedtolocatetherelevantkeyifitisnotsuppliedthenanattemptisusedtodecryptanyKEKRecipientInfostructures。inkeyfilenameuriTheprivatekeytousewhensigningordecrypting。Thismustmatchthecorrespondingcertificate。Ifthisoptionisnotspecifiedthentheprivatekeymustbeincludedinthecertificatefilespecifiedwiththereciporsignerfile。Whensigningthisoptioncanbeusedmultipletimestospecifysuccessivekeys。passinargTheprivatekeypasswordsource。Formoreinformationabouttheformatofargseeopensslpassphraseoptions(1)。keyoptname:parameterForsigningandencryptionthisoptioncanbeusedmultipletimestosetcustomisedparametersfortheprecedingkeyorcertificate。ItcancurrentlybeusedtosetRSAPSSforsigning,RSAOAEPforencryptionortomodifydefaultparametersforECDH。keyformDERPEMP12ENGINETunspecifiedbydefault。Seeopensslformatoptions(1)fordetails。engineidSeeEngineOptionsinopenssl(1)。Thisoptionisdeprecated。providernameproviderpathpathpropquerypropqSeeProviderOptionsinopenssl(1),provider(7),andproperty(7)。randfiles,writerandfileSeeRandomStateOptionsinopenssl(1)fordetails。EncryptionanddecryptionoptionsoriginatorfileAcertificateoftheoriginatoroftheencryptedmessage。NecessaryfordecryptionwhenKeyAgreementisinuseforasharedkey。recipfileWhendecryptingamessagethisspecifiesthecertificateoftherecipient。Thecertificatemustmatchoneoftherecipientsofthemessage。Whenencryptingamessagethisoptionmaybeusedmultipletimestospecifyeachrecipient。Thisformmustbeusedifcustomisedparametersarerequired(forexampletospecifyRSAOAEP)。OnlycertificatescarryingRSA,DiffieHellmanorECkeysaresupportedbythisoption。recipientcert。。。Thisisanalternativetousingtherecipoptionwhenencryptingamessage。Oneormorecertificatefilennamesmaybegiven。cipherTheencryptionalgorithmtouse。ForexampletripleDES(168bits)des3or256bitAESaes256。Anystandardalgorithmname(asusedbytheEVPgetcipherbyname()function)canalsobeusedprecededbyadash,forexampleaes128cbc。Seeopensslenc(1)foralistofcipherssupportedbyyourversionofOpenSSL。CurrentlytheAESvariantswithGCMmodearetheonlysupportedAEADalgorithms。IfnotspecifiedtripleDESisused。OnlyusedwithencryptandEncryptedDatacreatecommands。wrapcipherCipheralgorithmtouseforkeywrapwhenencryptingthemessageusingKeyAgreementforkeytransport。Thealgorithmspecifiedshouldbesuitableforkeywrap。aes128wrap,aes192wrap,aes256wrap,des3wrapUseAES128,AES192,AES256,or3DESEDE,respectively,towrapkey。DependingontheOpenSSLbuildoptionsused,des3wrapmaynotbesupported。debugdecryptThisoptionsetstheCMSDEBUGDECRYPTflag。Thisoptionshouldbeusedwithcaution:seethenotessectionbelow。SigningoptionsmddigestDigestalgorithmtousewhensigningorresigning。Ifnotpresentthenthedefaultdigestalgorithmforthesigningkeywillbeused(usuallySHA1)。signerfileAsigningcertificate。Whensigningorresigningamessage,thisoptioncanbeusedmultipletimesifmorethanonesignerisrequired。certfilefileAllowsadditionalcertificatestobespecified。Whensigningthesewillbeincludedwiththemessage。Whenverifyingthesewillbesearchedforthesignerscertificates。TheinputcanbeinPEM,DER,orPKCS12format。cadesWhenusedwithsign,addanESSsigningCertificateorESSsigningCertificateV2signedattributetotheSignerInfo,inordertomakethesignaturecomplywiththerequirementsforaCAdESBasicElectronicSignature(CAdESBES)。nodetachWhensigningamessageuseopaquesigning:thisformismoreresistanttotranslationbymailrelaysbutitcannotbereadbymailagentsthatdonotsupportSMIME。WithoutthisoptioncleartextsigningwiththeMIMEtypemultipartsignedisused。nocertsWhensigningamessagethesignerscertificateisnormallyincludedwiththisoptionitisexcluded。Thiswillreducethesizeofthesignedmessagebuttheverifiermusthaveacopyofthesignerscertificateavailablelocally(passedusingthecertfileoptionforexample)。noattrNormallywhenamessageissignedasetofattributesareincludedwhichincludethesigningtimeandsupportedsymmetricalgorithms。Withthisoptiontheyarenotincluded。nosmimecapExcludethelistofsupportedalgorithmsfromsignedattributes,otheroptionssuchassigningtimeandcontenttypearestillincluded。receiptrequestall,receiptrequestfirstForsignoptionincludeasignedreceiptrequest。Indicaterequestsshouldbeprovidedbyallrecipientorfirsttierrecipients(thosemaileddirectlyandnotfromamailinglist)。Ignoreditreceiptrequestfromisincluded。receiptrequestfromemailaddressForsignoptionincludeasignedreceiptrequest。Addanexplicitemailaddresswherereceiptsshouldbesupplied。receiptrequesttoemailaddressAddanexplicitemailaddresswheresignedreceiptsshouldbesentto。Thisoptionmustbutsuppliedifasignedreceiptisrequested。VerificationoptionssignerfileIfamessagehasbeenverifiedsuccessfullythenthesignerscertificate(s)willbewrittentothisfileiftheverificationwassuccessful。contentfilenameThisspecifiesafilecontainingthedetachedcontentforoperationstakingSMIMEinput,suchastheverifycommand。ThisisonlyusableiftheCMSstructureisusingthedetachedsignatureformwherethecontentisnotincluded。ThisoptionwilloverrideanycontentiftheinputformatisSMIMEanditusesthemultipartsignedMIMEcontenttype。nocontentverifyDonotverifysignedcontentsignatures。noattrverifyDonotverifysignedattributesignatures。nosigsDontverifymessagesignature。noverifyDonotverifythesignerscertificateofasignedmessage。nointernWhenverifyingamessagenormallycertificates(ifany)includedinthemessagearesearchedforthesigningcertificate。Withthisoptiononlythecertificatesspecifiedinthecertfileoptionareused。ThesuppliedcertificatescanstillbeusedasuntrustedCAshowever。cadesWhenusedwithverify,requireandchecksignercertificatedigest。SeetheNOTESsectionformoredetails。verifyretcodeExitnonzeroonverificationfailure。CAfilefile,noCAfile,CApathdir,noCApath,CAstoreuri,noCAstoreSeeTrustedCertificateOptionsinopensslverificationoptions(1)fordetails。OutputoptionskeyidUsesubjectkeyidentifiertoidentifycertificatesinsteadofissuernameandserialnumber。Thesuppliedcertificatemustincludeasubjectkeyidentifierextension。Supportedbysignandencryptoptions。econtenttypetypeSettheencapsulatedcontenttypetotypeifnotsuppliedtheDatatypeisused。ThetypeargumentcanbeanyvalidOIDnameineithertextornumericalformat。textThisoptionaddsplaintext(textplain)MIMEheaderstothesuppliedmessageifencryptingorsigning。Ifdecryptingorverifyingitstripsofftextheaders:ifthedecryptedorverifiedmessageisnotofMIMEtypetextplainthenanerroroccurs。certsoutfileAnycertificatescontainedintheinputmessagearewrittentofile。to,from,subjectTherelevantemailheaders。Theseareincludedoutsidethesignedportionofamessagesotheymaybeincludedmanually。IfsigningthenmanySMIMEmailclientscheckthesignerscertificatesemailaddressmatchesthatspecifiedintheFrom:address。PrintingoptionsnooutForthecmsoutoperationdonotoutputtheparsedCMSstructure。ThisisusefulifthesyntaxoftheCMSstructureisbeingchecked。printForthecmsoutoperationprintoutallfieldsoftheCMSstructure。Thisimpliesnoout。Thisismainlyusefulfortestingpurposes。nameoptoptionForthecmsoutoperationwhenprintoptionisinuse,specifiesprintingoptionsforstringfields。Formostcasesutf8isreasonablevalue。Seeopensslnamedisplayoptions(1)fordetails。receiptrequestprintFortheverifyoperationprintoutthecontentsofanysignedreceiptrequests。Validationoptionsallowproxycerts,attime,nochecktime,checksssig,crlcheck,crlcheckall,explicitpolicy,extendedcrl,ignorecritical,inhibitany,inhibitmap,noaltchains,partialchain,policy,policycheck,policyprint,purpose,suiteB128,suiteB128only,suiteB192,trustedfirst,usedeltas,authlevel,verifydepth,verifyemail,verifyhostname,verifyip,verifyname,x509strictissuerchecksSetvariousoptionsofcertificatechainverification。SeeVerificationOptionsinopensslverificationoptions(1)fordetails。Anyvalidationerrorscausethecommandtoexit。NOTESTheMIMEmessagemustbesentwithoutanyblanklinesbetweentheheadersandtheoutput。Somemailprogramswillautomaticallyaddablankline。Pipingthemaildirectlytosendmailisonewaytoachievethecorrectformat。ThesuppliedmessagetobesignedorencryptedmustincludethenecessaryMIMEheadersormanySMIMEclientswontdisplayitproperly(ifatall)。Youcanusethetextoptiontoautomaticallyaddplaintextheaders。Asignedandencryptedmessageisonewhereasignedmessageisthenencrypted。Thiscanbeproducedbyencryptinganalreadysignedmessage:seetheexamplessection。Thisversionoftheprogramonlyallowsonesignerpermessagebutitwillverifymultiplesignersonreceivedmessages。SomeSMIMEclientschokeifamessagecontainsmultiplesigners。Itispossibletosignmessagesinparallelbysigninganalreadysignedmessage。TheoptionsencryptanddecryptreflectcommonusageinSMIMEclients。StrictlyspeakingtheseprocessCMSenvelopeddata:CMSencrypteddataisusedforotherpurposes。Theresignoptionusesanexistingmessagedigestwhenaddinganewsigner。Thismeansthatattributesmustbepresentinatleastoneexistingsignerusingthesamemessagedigestorthisoperationwillfail。ThestreamandindefoptionsenablestreamingIOsupport。AsaresulttheencodingisBERusingindefinitelengthconstructedencodingandnolongerDER。Streamingissupportedfortheencryptoperationandthesignoperationifthecontentisnotdetached。StreamingisalwaysusedforthesignoperationwithdetacheddatabutsincethecontentisnolongerpartoftheCMSstructuretheencodingremainsDER。Ifthedecryptoptionisusedwithoutarecipientcertificatethenanattemptismadetolocatetherecipientbytryingeachpotentialrecipientinturnusingthesuppliedprivatekey。TothwarttheMMAattack(BleichenbachersattackonPKCS1v1。5RSApadding)allrecipientsaretriedwhethertheysucceedornotandifnorecipientsmatchthemessageisdecryptedusingarandomkeywhichwilltypicallyoutputgarbage。ThedebugdecryptoptioncanbeusedtodisabletheMMAattackprotectionandreturnanerrorifnorecipientcanbefound:thisoptionshouldbeusedwithcaution。ForafullerdescriptionseeCMSdecrypt(3))。CADESBASICELECTRONICSIGNATURE(CADESBES)ACAdESBasicElectronicSignature(CAdESBES),asdefinedintheEuropeanStandardETSIEN3191221V1。1。1,contains:ThesigneduserdataasdefinedinCMS(RFC3852);ContenttypeoftheEncapsulatedContentIMessagedigestoftheeContentOCTETSTRINGwithinencapContentIAnESSsigningCertificateorESSsigningCertificateV2attribute,asdefinedinEnhancedSecurityServices(ESS),RFC2634andRFC5035。AnESSsigningCertificateattributeonlyallowsforSHA1asdigestalgorithm。AnESSsigningCertificateV2attributeallowsforanydigestalgorithm。Thedigitalsignaturevaluecomputedontheuserdataand,whenpresent,onthesignedattributes。NOTEthatthecadesoptionappliestothesignorverifyoperations。Withthisoption,theverifyoperationalsorequiresthatthesigningCertificateattributeispresentandchecksthatthegivenidentifiersmatchtheverificationtrustchainbuiltduringtheverificationprocess。EXITCODES0Theoperationwascompletelysuccessfully。1Anerroroccurredparsingthecommandoptions。2Oneoftheinputfilescouldnotberead。3AnerroroccurredcreatingtheCMSfileorwhenreadingtheMIMEmessage。4Anerroroccurreddecryptingorverifyingthemessage。5Themessagewasverifiedcorrectlybutanerroroccurredwritingoutthesignerscertificates。COMPATIBILITYWITHPKCS7FORMATopensslsmime(1)canonlyprocesstheolderPKCS7format。opensslcmssupportsCryptographicMessageSyntaxformat。Useofsomefeatureswillresultinmessageswhichcannotbeprocessedbyapplicationswhichonlysupporttheolderformat。Thesearedetailedbelow。Theuseofthekeyidoptionwithsignorencrypt。TheoutformPEMoptionusesdifferentheaders。Thecompressoption。Thesecretkeyoptionwhenusedwithencrypt。TheuseofPSSwithsign。TheuseofOAEPornonRSAkeyswithencrypt。AdditionallytheEncryptedDatacreateanddatacreatetypecannotbeprocessedbytheolderopensslsmime(1)command。EXAMPLESCreateacleartextsignedmessage:opensslcmssigninmessage。txttextoutmail。msgsignermycert。pemCreateanopaquesignedmessageopensslcmssigninmessage。txttextoutmail。msgnodetachsignermycert。pemCreateasignedmessage,includesomeadditionalcertificatesandreadtheprivatekeyfromanotherfile:opensslcmssigninin。txttextoutmail。msgsignermycert。peminkeymykey。pemcertfilemycerts。pemCreateasignedmessagewithtwosigners,usekeyidentifier:opensslcmssigninmessage。txttextoutmail。msgsignermycert。pemsignerothercert。pemkeyidSendasignedmessageunderUnixdirectlytosendmail,includingheaders:opensslcmssigninin。txttextsignermycert。pemfromsteveopenssl。orgtosomeonesomewheresubjectSignedmessagesendmailsomeonesomewhereVerifyamessageandextractthesignerscertificateifsuccessful:opensslcmsverifyinmail。msgsigneruser。pemoutsignedtext。txtSendencryptedmailusingtripleDES:opensslcmsencryptinin。txtfromsteveopenssl。orgtosomeonesomewheresubjectEncryptedmessagedes3user。pemoutmail。msgSignandencryptmail:opensslcmssigninml。txtsignermy。pemtextopensslcmsencryptoutmail。msgfromsteveopenssl。orgtosomeonesomewheresubjectSignedandEncryptedmessagedes3user。pemNote:theencryptioncommanddoesnotincludethetextoptionbecausethemessagebeingencryptedalreadyhasMIMEheaders。Decryptamessage:opensslcmsdecryptinmail。msgrecipmycert。peminkeykey。pemTheoutputfromNetscapeformsigningisaPKCS7structurewiththedetachedsignatureformat。Youcanusethisprogramtoverifythesignaturebylinewrappingthebase64encodedstructureandsurroundingitwith:BEGINPKCS7ENDPKCS7andusingthecommand,opensslcmsverifyinformPEMinsignature。pemcontentcontent。txtalternativelyyoucanbase64decodethesignatureanduseopensslcmsverifyinformDERinsignature。dercontentcontent。txtCreateanencryptedmessageusing128bitCamellia:opensslcmsencryptinplain。txtcamellia128outmail。msgcert。pemAddasignertoanexistingmessage:opensslcmsresigninmail。msgsignernewsign。pemoutmail2。msgSignamessageusingRSAPSS:opensslcmssigninmessage。txttextoutmail。msgsignermycert。pemkeyoptrsapaddingmode:pssCreateanencryptedmessageusingRSAOAEP:opensslcmsencryptinplain。txtoutmail。msgrecipcert。pemkeyoptrsapaddingmode:oaepUseSHA256KDFwithanECDHcertificate:opensslcmsencryptinplain。txtoutmail。msgrecipecdhcert。pemkeyoptecdhkdfmd:sha256PrintCMSsignedbinarydatainhumanreadableform:opensslcmsinsigned。cmsbinaryinformDERcmsoutprintBUGSTheMIMEparserisntveryclever:itseemstohandlemostmessagesthatIvethrownatitbutitmaychokeonothers。Thecodecurrentlywillonlywriteoutthesignerscertificatetoafile:ifthesignerhasaseparateencryptioncertificatethismustbemanuallyextracted。Thereshouldbesomeheuristicthatdeterminesthecorrectencryptioncertificate。Ideallyadatabaseshouldbemaintainedofacertificatesforeachemailaddress。ThecodedoesntcurrentlytakenoteofthepermittedsymmetricencryptionalgorithmsassuppliedintheSMIMECapabilitiessignedattribute。thismeanstheuserhastomanuallyincludethecorrectencryptionalgorithm。Itshouldstorethelistofpermittedciphersinadatabaseandonlyusethose。Norevocationcheckingisdoneonthesignerscertificate。SEEALSOosslstorefile(7)HISTORYTheuseofmultiplesigneroptionsandtheresigncommandwerefirstaddedinOpenSSL1。0。0。ThekeyoptoptionwasaddedinOpenSSL1。0。2。SupportforRSAOAEPandRSAPSSwasaddedinOpenSSL1。0。2。TheuseofnonRSAkeyswithencryptanddecryptwasaddedinOpenSSL1。0。2。ThenoaltchainsoptionwasaddedinOpenSSL1。0。2b。ThenameoptoptionwasaddedinOpenSSL3。0。0。TheengineoptionwasdeprecatedinOpenSSL3。0。COPYRIGHTCopyright20082021TheOpenSSLProjectAuthors。AllRightsReserved。LicensedundertheApacheLicense2。0(theLicense)。YoumaynotusethisfileexceptincompliancewiththeLicense。YoucanobtainacopyinthefileLICENSEinthesourcedistributionorathttps:www。openssl。orgsourcelicense。html。3。0。220220316OPENSSLCMS(1SSL)
投诉 评论 转载

豪威发布新图像传感器OVB0A,依旧是2亿像素早些时候,我们曾报道过豪威发布的OVB0B这款传感器,并表示这是市面上的又一款2亿像素传感器。来到8月16日,豪威集团又发布了一款新的传感器OVB0A,表示为高端智能手机……如何从多维视角看我们的生活通常情况下,我们认为幸福就是创造自己认为的最好的生活,然后确定最想要的生活是什么,并为此去努力实现。比如说拥有一座花园洋房是一件幸福的事,于是努力工作赚钱,以便能够买得起……新建枣庄机场工程初步设计及概算取得批复11月4日,山东省交通运输厅联合民航华东地区管理局批复新建枣庄机场工程初步设计及概算,为年内开工建设奠定基础。新建枣庄机场工程是淮河生态经济带和鲁南经济圈的重大基础设施,……颜值经济大爆发,如何防止医美市场劣币驱逐良币?21世纪经济报道记者季媛媛上海报道尽管整体增速有所放缓,中国医疗美容市场依旧是全球最火热的医美市场之一。德勤的报告指出,伴随着资本的不断涌入,目前,中国医美行业已经形成了由上游……显卡3060和3060Ti区别3060和3060ti可以算是N卡阵营甜品级的中流砥柱,这两张卡也是非常热门的一组对比。目前由于网上二者的性能对比信息不太完善,因此虽然两张卡发售已经比较久了,但还是有必要在这……儿女不孝医院自残,晚年独居养老院的6位明星,过得不如普通人人呐,谁也逃不过生老病死这四劫。人到晚年,无论你名气有多大,也会和普通人一个样,都要正面对病痛和衰老。当然了,娱乐圈里的明星们,同样也不例外。前半生,他们过得风光无……跟老韩学UbuntuServer2204cms帮助手册跟老韩学LinuxSRE系列那些过往,如盛夏的月光,一如你青涩的脸庞。hanywhanyw:manopensslcmsgrepEv34;OPENSSLCMS(1SSL)O……72岁的郭台铭,收到最好的生日礼物这个完成交接班的代工帝国,是否能延续以往的辉煌?文《中国企业家》记者任娅斐编辑马吉英头图来源视觉中国富士康的造车业务再进一步,郭台铭有些激动。10……ampampquot无戏可拍ampampquot马苏力挺李小贾乃亮这辈子最恨的女人不是为他戴绿帽的李小璐而是将某万介绍给李小璐的皮条客马苏2017年底贾乃亮在直播间单纯直言我老婆做头发呢殊不知此时的李小璐却忙着和……凭什么不是夫妻关系,也可以住酒店一间房?前台谁规定的不能?相信很多人都会说不是夫妻关系,不能住在同一间客房,但是前台表示,只要遵守这几点是可以的。(此处已添加小程序,请到今日头条客户端查看)现如今,随着国民生活水平的提高,越来越……邱淑贞谈李连杰,李连杰一个四两拨千斤,拿走我衣服里的录像带邱淑贞是和王祖贤一个年代的女明星,虽然邱淑贞没有王祖贤那么出名,但是,邱淑贞的演艺路线很广,她和许多大牌明星都有合作过。论长相的话,邱淑贞是没有王祖贤好看的,毕竟王祖贤的……摩托罗拉不负众望,双曲面机身骁龙888Plus加持,仅199对于摩托罗拉手机品牌,想必网友们都并不陌生,虽说它在智能机时代刚开始时落伍了,但经过后期不断努力,也已经跟上了很多友商的步伐。如今的摩托罗拉还是比较不错的,旗下也拥有几款销量比……
韩国现代制铁将人工智能和大数据用于生产管理中国工业园项目在南非促发展创就业盘点中国古代十大名医,李时珍排第九,华佗排第3,第1名当之无8岁嗯哼骑平衡车书包重,霍思燕杜江被传感情不和,真有妹妹吗?苹果拿下高端市场第一,国产品牌高端之路道阻且长,将何去何从?3个孩子感染肺炎被送进医院,原因竟是加湿器!放醋放香水甚至还看看杜锋和杨鸣赛后怎么说!杨鸣杜指导是我的榜样为什么不能过分控制主食摄入,尤其是孕妇?吃主食的四个原则告别!35岁山东外援要离队!在中国赚3。5亿,进30个联赛进精品化研发实力获认可,游族网络斩获2022CGDA双料大奖文森特14中11砍27分5断热火力克雄鹿,字母哥连续缺阵每个人的人生,都藏在自己的认知里
回南天如何开空调除湿实缴注册资本不提供验资报告是否可行?赵一荻15岁就被张学良睡了?情感美文被岁月搁置的青春长期使用电脑对眼睛有多大危害《干宝树神黄祖》主要内容简介及赏析如何通过SaaS推动初创企业的增长?热议聚热点网 产品心理学014减少产品操作复杂度的4个方法iPhone6充一晚上电会烧坏么怎么正确给iPhone6充电双子座是几月到几月双子座是几月几号到几月几号佳能500D的快门速度是多少表夏十首其五

友情链接:中准网聚热点快百科快传网快生活快软网快好知文好找江西南阳嘉兴昆明铜陵滨州广东西昌常德梅州兰州阳江运城金华广西萍乡大理重庆诸暨泉州安庆南充武汉辽宁