package crt import ( "crypto/rsa" "crypto/x509" "encoding/pem" "errors" "fmt" "os" "github.com/youmark/pkcs8" ) func LoadRootCertAndKey(certFile, keyFile, password string) (*x509.Certificate, *rsa.PrivateKey, error) { fmt.Println(certFile, keyFile) // Загрузка корневого сертификата caCertPEM, err := os.ReadFile(certFile) if err != nil { return nil, nil, err } block, _ := pem.Decode(caCertPEM) if block == nil { return nil, nil, errors.New("failed to parse CA certificate PEM") } caCert, err := x509.ParseCertificate(block.Bytes) if err != nil { return nil, nil, err } // Загрузка зашифрованного приватного ключа keyPEM, err := os.ReadFile(keyFile) if err != nil { return nil, nil, err } block, _ = pem.Decode(keyPEM) if block == nil { return nil, nil, errors.New("failed to parse CA key PEM") } // Декодирование ключа с паролем decryptedKey, err := pkcs8.ParsePKCS8PrivateKey(block.Bytes, []byte(password)) if err != nil { return nil, nil, fmt.Errorf("failed to decrypt CA key: %v", err) } caKey, ok := decryptedKey.(*rsa.PrivateKey) if !ok { return nil, nil, err } return caCert, caKey, nil }