You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用PowerShell替代CertReq.exe创建证书请求?

用PowerShell替代certreq的INF文件创建证书请求

之前在命令提示符下生成证书请求时,必须编写繁琐的INF配置文件,示例如下:

[Version]
Signature="$Windows NT$"

[NewRequest]
FriendlyName = "SharePoint STS Certificate"
Subject = "CN=sts.contoso.com, O=Org, OU=Unit, L=City, S=State, C=Country"
KeyLength = 2048
KeyAlgorithm = RSA
KeyUsage = "CERT_KEY_ENCIPHERMENT_KEY_USAGE | CERT_DIGITAL_SIGNATURE_KEY_USAGE"
KeySpec = "AT_KEYEXCHANGE"
MachineKeySet = true
RequestType = Cert
ExportableEncrypted = true

[Strings]
szOID_ENHANCED_KEY_USAGE = "2.5.29.37"
szOID_PKIX_KP_SERVER_AUTH = "1.3.6.1.5.5.7.3.1"
szOID_PKIX_KP_CLIENT_AUTH = "1.3.6.1.5.5.7.3.2"
szOID_SUBJECT_ALT_NAME2 = "2.5.29.17"

[Extensions]
%szOID_ENHANCED_KEY_USAGE%="{text}%szOID_PKIX_KP_SERVER_AUTH%,"
_continue_ = "%szOID_PKIX_KP_CLIENT_AUTH%"
%szOID_SUBJECT_ALT_NAME2% = "{text}dns=server1&dns=server2"

执行以下命令即可生成证书请求:
certreq -new request.inf request.req

你可以用PowerShell的New-SelfSignedCertificate和Export-Certificate cmdlet实现相同效果,无需编写INF文件:

创建自签名证书并导出

1. 生成证书

运行以下PowerShell命令,参数完全对应上述INF文件的配置:

$certConfig = @{
    FriendlyName          = "SharePoint STS Certificate"
    Subject               = "CN=sts.contoso.com, O=Org, OU=Unit, L=City, S=State, C=Country"
    KeyLength             = 2048
    KeyAlgorithm          = "RSA"
    KeyUsage              = @("KeyEncipherment", "DigitalSignature")
    KeySpec               = "KeyExchange"
    CertStoreLocation     = "Cert:\LocalMachine\My"
    EnhancedKeyUsage      = @("Server Authentication", "Client Authentication")
    SubjectAlternativeName= @("dns=server1", "dns=server2")
    Exportable            = $true
}

$certificate = New-SelfSignedCertificate @certConfig

2. 导出证书文件

如果需要将证书导出到本地文件:

Export-Certificate -Cert $certificate -FilePath "C:\your\path\sts_certificate.cer" -Type CERT

生成证书请求(替代certreq)

如果你的目标是生成证书请求文件(而非直接创建证书),可以使用New-CertificateRequest cmdlet:

$requestConfig = @{
    Subject               = "CN=sts.contoso.com, O=Org, OU=Unit, L=City, S=State, C=Country"
    KeyLength             = 2048
    KeyAlgorithm          = "RSA"
    KeyUsage              = @("KeyEncipherment", "DigitalSignature")
    KeySpec               = "KeyExchange"
    EnhancedKeyUsage      = @("Server Authentication", "Client Authentication")
    SubjectAlternativeName= @("dns=server1", "dns=server2")
    Exportable            = $true
    MachineContext        = $true
}

$certRequest = New-CertificateRequest @requestConfig
$certRequest | Out-File "C:\your\path\request.req" -Encoding ASCII

内容的提问来源于stack exchange,提问作者Dennis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 09:35:57