如何使用PowerShell的New-SelfSignedCertificate替代Windows11不兼容的makecert
替代makecert的PowerShell自签名证书生成命令
针对你原来的makecert命令,以下是对应的PowerShell New-SelfSignedCertificate 实现步骤,全程需以管理员身份运行PowerShell:
步骤1:生成自签名根CA证书(对应第一条makecert命令)
这条命令会生成与原TempCA功能一致的根CA证书,并存储到本地计算机的「受信任的根证书颁发机构」中:
# 生成自签名根CA证书,有效期10年,支持签名、签发证书/CRL $caCert = New-SelfSignedCertificate -Subject "CN=TempCA" -KeySpec Signature ` -KeyUsage CertSign, CRLSign, DigitalSignature ` -KeyExportPolicy Exportable ` -NotAfter (Get-Date).AddYears(10) ` -HashAlgorithm SHA1 ` -CertStoreLocation "Cert:\LocalMachine\Root"
如果需要导出原命令生成的.cer(公钥)和私钥文件,可执行:
# 导出CA公钥到TempCA.cer Export-Certificate -Cert $caCert -FilePath "C:\YourPath\TempCA.cer" # 导出CA私钥到PFX文件(需设置强密码,如需兼容旧流程可转换为PVK) $caPassword = ConvertTo-SecureString "YourStrongPassword123" -AsPlainText -Force Export-PfxCertificate -Cert $caCert -FilePath "C:\YourPath\TempCA.pfx" -Password $caPassword
步骤2:用根CA签发交换证书(对应第二条makecert命令)
这条命令会用刚生成的TempCA签发MyTestCert证书,存储到本地计算机的「个人」证书存储,完全匹配原命令的密钥交换用途、可导出私钥等特性:
# 生成由TempCA签发的交换证书,有效期5年,支持密钥加密与数字签名 $testCert = New-SelfSignedCertificate -Subject "CN=MyTestCert" -KeySpec KeyExchange ` -KeyUsage KeyEncipherment, DigitalSignature ` -KeyExportPolicy Exportable ` -NotAfter (Get-Date).AddYears(5) ` -HashAlgorithm SHA1 ` -CertStoreLocation "Cert:\LocalMachine\My" ` -Signer $caCert
如需导出该证书的公钥或私钥,同样使用Export-Certificate和Export-PfxCertificate命令即可。
参数对应说明
| 原makecert参数 | 对应PowerShell参数/行为 |
|---|---|
-n "CN=TempCA" | -Subject "CN=TempCA" |
-r(自签名) | 未指定-Signer参数时,New-SelfSignedCertificate默认生成自签名证书 |
-sv TempCA.pvk | 用Export-PfxCertificate导出私钥(如需PVK格式,可通过工具转换PFX) |
TempCA.cer | 用Export-Certificate导出公钥 |
-sr LocalMachine | -CertStoreLocation "Cert:\LocalMachine\..." |
-ss My | 存储路径中的My(对应「个人」证书存储) |
-a sha1 | -HashAlgorithm SHA1 |
-sky exchange | -KeySpec KeyExchange |
-pe | -KeyExportPolicy Exportable |
-ic TempCA.cer -iv TempCA.pvk | -Signer $caCert(直接引用内存中的CA证书对象,无需读取文件) |
内容的提问来源于stack exchange,提问作者Eric
相关产品推荐
相关产品推荐

