You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Azure CLI从Azure Key Vault提取证书私钥用于httpd服务器

从Azure Key Vault提取证书私钥用于httpd服务器

Azure Key Vault中,证书对应的私钥是以Base64编码的PKCS#12(PFX)格式存储为Secret的,你通过az keyvault secret show拿到的字符串就是这个PFX文件的Base64编码。按照以下步骤提取httpd可用的PEM格式私钥:

步骤1:导出Base64编码的Secret内容到文件

执行Azure CLI命令,将Secret的原始Base64内容导出到文本文件:

az keyvault secret show --vault-name <你的密钥库名称> --name <证书名称> --query "value" -o tsv > cert-base64.txt

注意:<证书名称>要和你下载crt时使用的证书名称完全一致。

步骤2:将Base64解码为PFX文件

根据操作系统选择解码命令:

  • Linux/macOS:
    base64 -d cert-base64.txt > cert.pfx
    
  • Windows:
    certutil -decode cert-base64.txt cert.pfx
    

步骤3:从PFX文件提取PEM格式私钥

使用openssl工具将PFX中的私钥提取为httpd支持的PEM格式:

openssl pkcs12 -in cert.pfx -nocerts -out private-key.pem

执行时会提示输入PFX文件的密码——Key Vault生成的PFX默认无密码,直接按回车即可。

可选:如果需要提取完整证书链(而非单独的crt文件),可以执行:

openssl pkcs12 -in cert.pfx -nokeys -out cert-chain.pem

步骤4:移除私钥的密码保护(可选)

如果私钥被加密(极少数情况),可以用以下命令移除密码,方便httpd直接使用:

openssl rsa -in private-key.pem -out unencrypted-private-key.pem

配置httpd

将生成的私钥文件(private-key.pem或unencrypted-private-key.pem)和你之前下载的crt文件,配置到httpd的SSL模块中:

SSLCertificateFile /path/to/your/certificate.crt
SSLCertificateKeyFile /path/to/your/unencrypted-private-key.pem

注意事项

  • 确保你的Azure账号拥有Key Vault的Secret Get权限,否则az keyvault secret show命令会返回权限错误。
  • 提前安装openssl工具:Linux可通过apt install openssl或yum install openssl安装,Windows可使用Git Bash或官方OpenSSL二进制包。

内容的提问来源于stack exchange,提问作者Rhodian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 17:59:59