You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否将Microsoft RSA Root Certificate Authority 2017证书存入Azure Key Vault?

解决方案:存储Microsoft RSA Root CA 2017到Azure Key Vault

错误原因

az keyvault certificate import命令默认要求导入的证书包含私钥,但Microsoft RSA Root Certificate Authority 2017是根CA证书,仅含公钥无私钥,因此触发BadParameter错误。

两种存储方式

方式1:作为Secret存储(推荐用于信任链验证场景)

直接将公钥证书以Secret形式存入Key Vault,命令如下:

az keyvault secret set --vault-name vault01 --name "MicrosoftRSA2017" --file "Microsoft RSA Root Certificate Authority 2017.crt" --content-type "application/x-x509-ca-cert"

方式2:作为Certificate对象存储

若需将其作为Key Vault的Certificate资源存储,需先定义允许无私钥的证书策略,再执行导入:

  1. 创建策略文件policy.json,内容如下:
{
  "issuerParameters": {
    "name": "Unknown"
  },
  "x509CertificateProperties": {
    "subject": "CN=Microsoft RSA Root Certificate Authority 2017",
    "keyUsage": ["cRLSign", "keyCertSign"],
    "validityInMonths": 120
  },
  "keyProperties": {
    "exportable": false,
    "keyType": "RSA",
    "keySize": 2048,
    "reuseKey": false
  }
}
  1. 执行导入命令并指定策略:
az keyvault certificate import --vault-name vault01 --name "MicrosoftRSA2017" --file "Microsoft RSA Root Certificate Authority 2017.crt" --policy @policy.json

内容的提问来源于stack exchange,提问作者goc

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 07:03:20