語言

X509FindType 列舉

定義

指定 Find(X509FindType, Object, Boolean) 方法搜尋的值類型。

public enum class X509FindType
public enum X509FindType
type X509FindType = 
Public Enum X509FindType
繼承
X509FindType

欄位

名稱 值 Description
FindByThumbprint 0

findValue方法的Find(X509FindType, Object, Boolean)參數必須是代表憑證拇指印本的字串。

FindBySubjectName 1

findValue該方法的Find(X509FindType, Object, Boolean)參數必須是代表憑證主旨名稱的字串。 這種搜尋方式比列舉值所提供的 FindBySubjectDistinguishedName 搜尋要不精確。 利用該 FindBySubjectName 值,方法 Find(X509FindType, Object, Boolean) 會根據所提供的值執行大小寫不區分的字串比較。 例如,如果你把「MyCert」傳給 Find(X509FindType, Object, Boolean) 該方法,它會找到所有包含該字串的主體名稱憑證,不管其他主體值如何。 以 distinguished name 搜尋則是更精確的搜尋方式。

FindBySubjectDistinguishedName 2

findValue該方法的Find(X509FindType, Object, Boolean)參數必須是代表證書主題區別名稱的字串。 這比列 FindBySubjectName 舉值所提供的搜尋更為具體。 利用該 FindBySubjectDistinguishedName 值,該 Find(X509FindType, Object, Boolean) 方法對整個區別名稱進行大小寫不區分的字串比較。 以主題名稱搜尋則較不精確。

FindByIssuerName 3

findValue方法的Find(X509FindType, Object, Boolean)參數必須是代表憑證發行者名稱的字串。 這種搜尋方式比列舉值所提供的 FindByIssuerDistinguishedName 搜尋要不精確。 利用該 FindByIssuerName 值,方法 Find(X509FindType, Object, Boolean) 會根據所提供的值執行大小寫不區分的字串比較。 例如,如果你把「MyCA」傳給 Find(X509FindType, Object, Boolean) 這個方法,它會找到所有發行者名稱中包含該字串的憑證,不管其他發行者的值如何。

FindByIssuerDistinguishedName 4

findValue該方法的Find(X509FindType, Object, Boolean)參數必須是代表憑證發行者特殊名稱的字串。 這比列 FindByIssuerName 舉值所提供的搜尋更為具體。 利用該 FindByIssuerDistinguishedName 值,該 Find(X509FindType, Object, Boolean) 方法對整個區別名稱進行大小寫不區分的字串比較。 以發行人名稱搜尋則較不精確。

FindBySerialNumber 5

findValue方法的Find(X509FindType, Object, Boolean)參數必須是代表憑證對話框中顯示但不包含空格的字串,或是方法回傳GetSerialNumberString()的序號。

FindByTimeValid 6

findValue該方法的Find(X509FindType, Object, Boolean)參數必須是DateTime當地時間的值。 你可以用來 Now 查找所有目前有效的證書。

FindByTimeNotYetValid 7

findValue該方法的Find(X509FindType, Object, Boolean)參數必須是DateTime當地時間的值。 價值不一定是未來。 例如,你可以用FindByTimeNotYetValid來找出在今年有效憑證,方法是將去年最後一天的某操作Find(X509FindType, Object, Boolean)結果FindByTimeNotYetValid與 Find(X509FindType, Object, Boolean) 的FindByTimeValid操作Now結果相交。

FindByTimeExpired 8

findValue該方法的Find(X509FindType, Object, Boolean)參數必須是DateTime當地時間的值。 例如,你可以從該Find(X509FindType, Object, Boolean)年FindByTimeExpired最後一天的操作Find(X509FindType, Object, Boolean)結果Now中剔除所有有效至年底的證書。

FindByTemplateName 9

findValue方法的Find(X509FindType, Object, Boolean)參數必須是代表憑證範本名稱的字串,例如「ClientAuth」。 範本名稱是 X509 版本 3 的擴充功能,用以指定憑證的用途。

FindByApplicationPolicy 10

findValue方法的Find(X509FindType, Object, Boolean)參數必須是代表應用程式政策友善名稱或憑證物件識別碼(OID,或 Oid)的字串。 例如,可以使用「Encrypting File System」或「1.3.6.1.4.1.311.10.3.4」。 對於將被本地化的應用程式,必須使用 OID 值,因為友善名稱是本地化的。

FindByCertificatePolicy 11

findValue方法的Find(X509FindType, Object, Boolean)參數必須是代表憑證政策的友善名稱或物件識別碼(OID,或 Oid)的字串。 最佳實務是使用 OID,例如 “1.3.6.1.4.1.311.10.3.4”。 對於將要本地化的應用程式,必須使用 OID,因為友善名稱是本地化的。

FindByExtension 12

findValue該方法的Find(X509FindType, Object, Boolean)參數必須是描述要查找的擴展的字串。 物件識別碼(OID)最常用來指示方法 Find(X509FindType, Object, Boolean) 搜尋所有副檔名與該 OID 值相符的憑證。

FindByKeyUsage 13

findValue該方法的Find(X509FindType, Object, Boolean)參數必須是代表金鑰使用情況的字串,或是代表包含所有請求金鑰使用情況的位元遮罩的整數。 對於字串值,一次只能指定一個金鑰使用,但 Find(X509FindType, Object, Boolean) 此方法可以級聯序列方式取得所請求使用頻率的交集。 例如, findValue 參數可以設定為「KeyEncipherment」或整數(0x30 表示「KeyEncipherment」與「DataEncipherment」)。 也可以使用列舉的 X509KeyUsageFlags 數值。

FindBySubjectKeyIdentifier 14

findValue該方法的Find(X509FindType, Object, Boolean)參數必須是代表主體金鑰識別碼的字串,以十六進位表示,例如「F3E815D45E83B8477B9284113C64EF208E897112」,如 UI 中所示。

範例

以下範例會開啟目前使用者的個人憑證儲存庫,只找到有效的憑證,允許使用者選擇憑證,然後將憑證資訊寫入主控台。 產出取決於你選擇的證書。

using System;
using System.Security.Cryptography;
using System.Security.Permissions;
using System.IO;
using System.Security.Cryptography.X509Certificates;

class CertSelect
{
    static void Main()
    {
        X509Store store = new X509Store("MY",StoreLocation.CurrentUser);
        store.Open(OpenFlags.ReadOnly | OpenFlags.OpenExistingOnly);

        X509Certificate2Collection collection = (X509Certificate2Collection)store.Certificates;
        X509Certificate2Collection fcollection = (X509Certificate2Collection)collection.Find(X509FindType.FindByTimeValid,DateTime.Now,false);
        X509Certificate2Collection scollection = X509Certificate2UI.SelectFromCollection(fcollection, "Test Certificate Select","Select a certificate from the following list to get information on that certificate",X509SelectionFlag.MultiSelection);
        Console.WriteLine("Number of certificates: {0}{1}",scollection.Count,Environment.NewLine);

        foreach (X509Certificate2 x509 in scollection)
        {
            try
            {
                byte[] rawdata = x509.RawData;
                Console.WriteLine("Content Type: {0}{1}",X509Certificate2.GetCertContentType(rawdata),Environment.NewLine);
                Console.WriteLine("Friendly Name: {0}{1}",x509.FriendlyName,Environment.NewLine);
                Console.WriteLine("Certificate Verified?: {0}{1}",x509.Verify(),Environment.NewLine);
                Console.WriteLine("Simple Name: {0}{1}",x509.GetNameInfo(X509NameType.SimpleName,true),Environment.NewLine);
                Console.WriteLine("Signature Algorithm: {0}{1}",x509.SignatureAlgorithm.FriendlyName,Environment.NewLine);
                Console.WriteLine("Public Key: {0}{1}",x509.PublicKey.Key.ToXmlString(false),Environment.NewLine);
                Console.WriteLine("Certificate Archived?: {0}{1}",x509.Archived,Environment.NewLine);
                Console.WriteLine("Length of Raw Data: {0}{1}",x509.RawData.Length,Environment.NewLine);
                X509Certificate2UI.DisplayCertificate(x509);
                x509.Reset();
            }
            catch (CryptographicException)
            {
                Console.WriteLine("Information could not be written out for this certificate.");
            }
        }
        store.Close();
    }
}
Imports System.Security.Cryptography
Imports System.Security.Permissions
Imports System.IO
Imports System.Security.Cryptography.X509Certificates

Class CertSelect

    Shared Sub Main()

        Dim store As New X509Store("MY", StoreLocation.CurrentUser)
        store.Open(OpenFlags.ReadOnly Or OpenFlags.OpenExistingOnly)

        Dim collection As X509Certificate2Collection = CType(store.Certificates, X509Certificate2Collection)
        Dim fcollection As X509Certificate2Collection = CType(collection.Find(X509FindType.FindByTimeValid, DateTime.Now, False), X509Certificate2Collection)
        Dim scollection As X509Certificate2Collection = X509Certificate2UI.SelectFromCollection(fcollection, "Test Certificate Select", "Select a certificate from the following list to get information on that certificate", X509SelectionFlag.MultiSelection)
        Console.WriteLine("Number of certificates: {0}{1}", scollection.Count, Environment.NewLine)
         
        For Each x509 As X509Certificate2 In scollection
            Try
                Dim rawdata As Byte() = x509.RawData
                Console.WriteLine("Content Type: {0}{1}", X509Certificate2.GetCertContentType(rawdata), Environment.NewLine)
                Console.WriteLine("Friendly Name: {0}{1}", x509.FriendlyName, Environment.NewLine)
                Console.WriteLine("Certificate Verified?: {0}{1}", x509.Verify(), Environment.NewLine)
                Console.WriteLine("Simple Name: {0}{1}", x509.GetNameInfo(X509NameType.SimpleName, True), Environment.NewLine)
                Console.WriteLine("Signature Algorithm: {0}{1}", x509.SignatureAlgorithm.FriendlyName, Environment.NewLine)
                Console.WriteLine("Public Key: {0}{1}", x509.PublicKey.Key.ToXmlString(False), Environment.NewLine)
                Console.WriteLine("Certificate Archived?: {0}{1}", x509.Archived, Environment.NewLine)
                Console.WriteLine("Length of Raw Data: {0}{1}", x509.RawData.Length, Environment.NewLine)
                X509Certificate2UI.DisplayCertificate(x509)
                x509.Reset()         
             Catch cExcept As CryptographicException
                 Console.WriteLine("Information could not be written out for this certificate.")
             End Try
        Next x509

        store.Close()
    End Sub
End Class

備註

X509FindType識別方法參數中findValueFind所提供的值類型。 你可以用 X509FindType 主題名稱、指紋、序號、有效日期範圍或其他數值搜尋合 X509Certificate2 集。

你可以結合 FindByTime 多種價值類型,找出在特定時間範圍內有效的證書。 使用 FindByTimeValid、FindByTimeNotYetValid 和 FindByTimeExpired 在特定時間內回傳的憑證聯集,代表查詢集合中的所有憑證。

適用於