You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在.NET中实现指定PowerShell命令获取证书信息用于REST调用

.NET实现指定证书指纹查找并用于REST调用

功能说明

对应PowerShell命令 Get-ChildItem -Path 'cert:\LocalMachine\My' | Where-Object { $_.Thumbprint -eq '<ThumbPrint>' },以下是.NET(C#)的实现代码,用于从本地机器的LocalMachine\My证书存储区查找指定指纹的证书,并将其用于REST API调用。

完整代码示例

using System;
using System.Net.Http;
using System.Security.Cryptography.X509Certificates;
using System.Threading.Tasks;

class CertificateRestClient
{
    static async Task Main(string[] args)
    {
        // 替换为目标证书的指纹,注意去掉空格并统一大小写
        string targetThumbprint = "<ThumbPrint>".Replace(" ", "").ToUpperInvariant();

        // 打开LocalMachine下的"My"(个人)证书存储区
        using var store = new X509Store(StoreName.My, StoreLocation.LocalMachine);
        store.Open(OpenFlags.ReadOnly);

        try
        {
            // 根据指纹查找证书
            var matchingCerts = store.Certificates.Find(
                X509FindType.FindByThumbprint,
                targetThumbprint,
                validOnly: false // false表示包含过期/无效证书,按需改为true
            );

            if (matchingCerts.Count == 0)
            {
                throw new InvalidOperationException($"未找到指纹为 {targetThumbprint} 的证书");
            }

            X509Certificate2 targetCertificate = matchingCerts[0];
            Console.WriteLine($"成功找到证书:{targetCertificate.Subject}");

            // 使用证书发起REST请求(双向TLS认证场景)
            using var httpHandler = new HttpClientHandler();
            httpHandler.ClientCertificates.Add(targetCertificate);

            using var httpClient = new HttpClient(httpHandler);
            // 替换为实际的API端点
            var response = await httpClient.GetAsync("https://your-target-api.com/endpoint");
            response.EnsureSuccessStatusCode();

            string responseContent = await response.Content.ReadAsStringAsync();
            Console.WriteLine("API响应内容:");
            Console.WriteLine(responseContent);
        }
        catch (Exception ex)
        {
            Console.WriteLine($"执行出错:{ex.Message}");
        }
        finally
        {
            store.Close();
        }
    }
}

关键细节说明

  • 指纹格式处理:证书存储区中的指纹以大写无空格的形式存储,因此需要对输入的指纹做去空格、转大写处理,避免匹配失败。
  • 存储区权限:访问LocalMachine级别的证书存储区通常需要管理员权限运行程序,否则可能无法读取证书。
  • validOnly参数:设为true时仅查找有效证书(未过期、信任链完整);设为false会返回所有匹配指纹的证书,包括过期或未受信任的证书,可根据需求调整。
  • 私钥要求:如果REST API需要双向TLS认证,确保目标证书包含可访问的私钥,且程序拥有读取私钥的权限。

内容的提问来源于stack exchange,提问作者Sudhansu Bal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 15:15:09