brief description what I've done and what I would like to achieve:
- I was trying to add certificate to azure key vault via UI:
- Got those certificates as ca.crt (
openssl req -new -x509 -days 1826 -key ca.key -out ca.crt) and ca.key (openssl genrsa -des3 -out ca.key 2048) but azure key vault requires certificates in .pem or .pfx format - I decided to move cert and key into pem format: key:
openssl rsa -in ca.key -text > ca_key.pemcert:openssl x509 -in ca.crt -out ca.pemthen copied ca_key.pem inside ca.pem - I was trying with only cert + key and key extra data (binaries or sth)
- I was getting error from UI:
The specified PEM X.509 certificate content is in an unexpected format. Please check if certificate is in valid PEM format. - I decided to install azure CLI and pass those in pfx format:
openssl pkcs12 -export -out ca.pfx -inkey ca.key -in ca.crtand that works properly I'm able to see created cert in key vault cerfiticates
and there problem begins. I would like to get certificate with azure node library, extract separate key and cert to use them. What I've achieved so far:
const secretClient = new SecretClient(keyVaultUrl, credential);
const certificateSecret = await secretClient.getSecret(certificateName);
const PKCS12Certificate = certificateSecret.value!;
fs.writeFileSync("myCertificate.p12", PKCS12Certificate);
I got file and as documentation says: https://www.npmjs.com/package/@azure/keyvault-certificates#getting-the-full-information-of-a-certificate
I was trying to execute:
openssl pkcs12 -in myCertificate.p12 -out myCertificate.crt.pem -clcerts -nokeys
to extract ca certificate from p12 but I'm still getting error:
34359836736:error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag:crypto/asn1/tasn_dec.c:1149:
34359836736:error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error:crypto/asn1/tasn_dec.c:309:Type=PKCS12
any ideas what I'm doing wrong ?