You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用PowerShell脚本在100+服务器安装绑定通配符SSL?有无微软工具?

批量在多台服务器安装并绑定通配符SSL证书

一、PowerShell脚本实现方案

前置条件

  • 所有目标服务器已开启WinRM(可通过Enable-PSRemoting -Force提前配置,需管理员权限)
  • 持有目标服务器的管理员权限
  • 准备好通配符证书的PFX文件及对应密码

示例脚本

# 配置核心参数
$certLocalPath = "C:\LocalFiles\wildcard-yourdomain.pfx"
$certSecurePass = ConvertTo-SecureString "YourCertPassword123" -AsPlainText -Force
$serverList = Get-Content "C:\ServerInventory\TargetServers.txt" # 每行一个服务器名/IP
$targetCertStore = "Cert:\LocalMachine\My"
$iisTargetSite = "Default Web Site" # 需绑定的IIS网站名
$sslPort = 443
$wildcardHost = "*.yourdomain.com"

# 遍历服务器执行批量操作
foreach ($server in $serverList) {
    try {
        # 建立远程会话
        $remoteSession = New-PSSession -ComputerName $server -ErrorAction Stop
        
        # 复制证书到远程服务器临时目录
        $remoteTempPath = "C:\Temp\wildcard-cert.pfx"
        Copy-Item -Path $certLocalPath -Destination $remoteTempPath -ToSession $remoteSession
        
        # 导入证书到远程服务器本地计算机存储
        Invoke-Command -Session $remoteSession -ScriptBlock {
            param($tempPath, $securePass, $storePath)
            Import-PfxCertificate -FilePath $tempPath -Password $securePass -CertStoreLocation $storePath
        } -ArgumentList $remoteTempPath, $certSecurePass, $targetCertStore
        
        # 获取证书指纹
        $certThumbprint = Invoke-Command -Session $remoteSession -ScriptBlock {
            (Get-ChildItem Cert:\LocalMachine\My | Where-Object { $_.Subject -like "*CN=$using:wildcardHost*" }).Thumbprint
        }
        
        # 绑定证书到IIS网站
        Invoke-Command -Session $remoteSession -ScriptBlock {
            param($siteName, $port, $thumbprint, $hostHeader)
            # 创建HTTPS绑定(若不存在)
            if (-not (Get-WebBinding -Name $siteName -Port $port -Protocol https)) {
                New-WebBinding -Name $siteName -Port $port -Protocol https -HostHeader $hostHeader
            }
            # 关联证书到绑定
            Set-WebBinding -Name $siteName -Port $port -Protocol https -PropertyName SSLFlags -Value 1
            Get-WebBinding -Name $siteName -Port $port -Protocol https | ForEach-Object {
                $_.AddSslCertificate($thumbprint, "My")
            }
        } -ArgumentList $iisTargetSite, $sslPort, $certThumbprint, $wildcardHost
        
        # 清理远程临时文件
        Invoke-Command -Session $remoteSession -ScriptBlock { Remove-Item $using:remoteTempPath -Force }
        
        Write-Host "✅ 服务器 $server 操作完成"
        Remove-PSSession $remoteSession
    }
    catch {
        Write-Host "❌ 服务器 $server 操作失败: $_" -ForegroundColor Red
        if ($remoteSession) { Remove-PSSession $remoteSession }
    }
}

注意事项

  • 脚本需以管理员身份运行
  • 若目标服务器未安装IIS管理模块,需先执行Install-WindowsFeature Web-Server, Web-Mgmt-Service
  • 可根据需求调整绑定规则(如无需HostHeader、绑定到特定IP等)

二、微软官方工具方案

1. 组策略(Group Policy)

  • 适合域环境下批量部署证书:
    • 在组策略管理控制台创建新GPO,导航至计算机配置 > Windows设置 > 安全设置 > 公钥策略,导入PFX证书并指定分发范围到目标服务器组
    • 配合GPO启动/登录脚本执行PowerShell绑定逻辑,实现全自动化

2. Web Deploy(MSDeploy)

  • 官方Web部署工具,支持批量同步IIS配置:
    • 先在一台模板服务器上配置好SSL绑定,再通过MSDeploy将配置同步至所有目标服务器
    • 核心命令示例:
      msdeploy.exe -verb:sync -source:webserver,computername=TemplateServer -dest:webserver,computername=TargetServer -enableRule:DoNotDeleteRule
      

3. IIS Administration API

  • 官方REST API,可通过编程方式批量管理多台IIS服务器的SSL绑定,适合集成到现有自动化平台

内容的提问来源于stack exchange,提问作者samir patil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 06:55:30