使用New-SelfSignedCertificate向TrustedPublishers存储区创建证书失败
在Windows 10的PowerShell中向TrustedPublishers存储区创建自签名证书的解决方法
问题描述
尝试执行以下命令直接在Cert:\LocalMachine\TrustedPublishers存储区创建自签名证书:
New-SelfSignedCertificate -Subject 'ABC' -CertStoreLocation Cert:\LocalMachine\TrustedPublishers
触发错误提示:
New-SelfSignedCertificate : Cannot find path 'Cert:\LocalMachine\TrustedPublishers' because it does not exist. At line:1 char:2 + New-SelfSignedCertificate -Subject 'B0014' -CertStoreLocation Cert:\ ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : ObjectNotFound: (Cert:\LocalMachine\TrustedPublishers:String) [New-SelfSignedCertificate ], ItemNotFoundException + FullyQualifiedErrorId : PathNotFound,Microsoft.CertificateServices.Commands.NewSelfSignedCertificateCommand
实际LocalMachine\TrustedPublishers存储区是存在的,但命令无法识别该路径。
原因说明
New-SelfSignedCertificate命令无法直接向TrustedPublishers存储区写入证书,因为该存储区属于系统逻辑存储区,受权限和存储机制限制,不支持直接创建操作,必须通过"先创建后迁移"的方式完成。
解决方案
步骤1:先创建证书到可直接写入的存储区
将自签名证书创建到LocalMachine\My(个人存储区),这是支持直接写入的存储区:
$cert = New-SelfSignedCertificate -Subject 'ABC' -CertStoreLocation Cert:\LocalMachine\My
步骤2:将证书迁移到TrustedPublishers存储区
提供两种可靠的迁移方式:
方式一:使用Copy-Item直接复制
Copy-Item -Path $cert.PSPath -Destination Cert:\LocalMachine\TrustedPublishers
方式二:通过导出再导入(适合脚本化场景)
# 临时导出证书到本地文件 $tempCertPath = Join-Path -Path $env:TEMP -ChildPath "temp_trusted_cert.cer" Export-Certificate -Cert $cert -FilePath $tempCertPath -Type CERT # 导入到TrustedPublishers存储区 Import-Certificate -FilePath $tempCertPath -CertStoreLocation Cert:\LocalMachine\TrustedPublishers # 删除临时文件 Remove-Item -Path $tempCertPath -Force
注意事项
- 执行所有命令时,必须以管理员身份运行PowerShell,否则会出现权限不足的错误。
TrustedPublishers存储区主要用于存储代码签名证书的发布者信任列表,确保迁移的证书符合使用场景要求。
内容的提问来源于stack exchange,提问作者Alex
相关产品推荐
相关产品推荐

