You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用OpenSSL结合Windows本地存储证书解密SMIME加密Outlook msg文件

解决PKI加密Outlook MSG文件解密问题

问题背景

  • 持有单个PKI证书加密的Outlook MSG文件
  • 对应解密证书(含私钥)存储在Windows的Cert:\CurrentUser\My\路径下
  • 尝试Unprotect-CmsMessage命令报错“no encrypted data”,转而用OpenSSL但无法导出私钥,希望让OpenSSL直接调用Windows本地证书存储

可行解决方案

方案1:用PowerShell结合.NET类处理SMIME解密

Unprotect-CmsMessage仅支持CMS加密内容,而Outlook加密邮件采用SMIME格式,需借助.NET的System.Security.Cryptography.Pkcs类处理,脚本示例:

# 加载.NET程序集
Add-Type -AssemblyName System.Security

# 读取目标MSG文件
$msgPath = "C:\your_path\mail.msg"
$msgBytes = [System.IO.File]::ReadAllBytes($msgPath)

# 初始化SMIME解密对象
$envelopedCms = New-Object System.Security.Cryptography.Pkcs.EnvelopedCms
$envelopedCms.Decode($msgBytes)

# 调用本地证书存储解密
$envelopedCms.Decrypt()

# 输出解密后的内容
$decryptedBytes = $envelopedCms.ContentInfo.Content
[System.IO.File]::WriteAllBytes("C:\your_path\decrypted_content.txt", $decryptedBytes)

方案2:让OpenSSL调用Windows证书存储

OpenSSL本身不直接支持Windows证书存储,但可通过capi引擎对接Windows CryptoAPI实现:

  1. 确保使用的Windows版OpenSSL默认包含capi引擎(多数发行版已预装)
  2. 执行以下命令解密:
openssl smime -decrypt -in mail.msg -engine capi -recip "你的证书主题名称"
  • 证书主题名称可通过certutil -user -store My命令查看
  • 该命令会直接访问当前用户的Windows证书存储,无需导出私钥;若证书受PIN保护,执行时会弹出验证窗口

注意事项

  • 需以拥有证书私钥访问权限的用户身份执行脚本或命令
  • 解密后的内容为邮件原始数据,可保存为txt或进一步解析为MSG格式

内容的提问来源于stack exchange,提问作者Migel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 03:33:16