如何用PowerShell脚本在100+服务器安装绑定通配符SSL?有无微软工具?
批量在多台服务器安装并绑定通配符SSL证书
一、PowerShell脚本实现方案
前置条件
- 所有目标服务器已开启WinRM(可通过
Enable-PSRemoting -Force提前配置,需管理员权限) - 持有目标服务器的管理员权限
- 准备好通配符证书的PFX文件及对应密码
示例脚本
# 配置核心参数 $certLocalPath = "C:\LocalFiles\wildcard-yourdomain.pfx" $certSecurePass = ConvertTo-SecureString "YourCertPassword123" -AsPlainText -Force $serverList = Get-Content "C:\ServerInventory\TargetServers.txt" # 每行一个服务器名/IP $targetCertStore = "Cert:\LocalMachine\My" $iisTargetSite = "Default Web Site" # 需绑定的IIS网站名 $sslPort = 443 $wildcardHost = "*.yourdomain.com" # 遍历服务器执行批量操作 foreach ($server in $serverList) { try { # 建立远程会话 $remoteSession = New-PSSession -ComputerName $server -ErrorAction Stop # 复制证书到远程服务器临时目录 $remoteTempPath = "C:\Temp\wildcard-cert.pfx" Copy-Item -Path $certLocalPath -Destination $remoteTempPath -ToSession $remoteSession # 导入证书到远程服务器本地计算机存储 Invoke-Command -Session $remoteSession -ScriptBlock { param($tempPath, $securePass, $storePath) Import-PfxCertificate -FilePath $tempPath -Password $securePass -CertStoreLocation $storePath } -ArgumentList $remoteTempPath, $certSecurePass, $targetCertStore # 获取证书指纹 $certThumbprint = Invoke-Command -Session $remoteSession -ScriptBlock { (Get-ChildItem Cert:\LocalMachine\My | Where-Object { $_.Subject -like "*CN=$using:wildcardHost*" }).Thumbprint } # 绑定证书到IIS网站 Invoke-Command -Session $remoteSession -ScriptBlock { param($siteName, $port, $thumbprint, $hostHeader) # 创建HTTPS绑定(若不存在) if (-not (Get-WebBinding -Name $siteName -Port $port -Protocol https)) { New-WebBinding -Name $siteName -Port $port -Protocol https -HostHeader $hostHeader } # 关联证书到绑定 Set-WebBinding -Name $siteName -Port $port -Protocol https -PropertyName SSLFlags -Value 1 Get-WebBinding -Name $siteName -Port $port -Protocol https | ForEach-Object { $_.AddSslCertificate($thumbprint, "My") } } -ArgumentList $iisTargetSite, $sslPort, $certThumbprint, $wildcardHost # 清理远程临时文件 Invoke-Command -Session $remoteSession -ScriptBlock { Remove-Item $using:remoteTempPath -Force } Write-Host "✅ 服务器 $server 操作完成" Remove-PSSession $remoteSession } catch { Write-Host "❌ 服务器 $server 操作失败: $_" -ForegroundColor Red if ($remoteSession) { Remove-PSSession $remoteSession } } }
注意事项
- 脚本需以管理员身份运行
- 若目标服务器未安装IIS管理模块,需先执行
Install-WindowsFeature Web-Server, Web-Mgmt-Service - 可根据需求调整绑定规则(如无需HostHeader、绑定到特定IP等)
二、微软官方工具方案
1. 组策略(Group Policy)
- 适合域环境下批量部署证书:
- 在组策略管理控制台创建新GPO,导航至计算机配置 > Windows设置 > 安全设置 > 公钥策略,导入PFX证书并指定分发范围到目标服务器组
- 配合GPO启动/登录脚本执行PowerShell绑定逻辑,实现全自动化
2. Web Deploy(MSDeploy)
- 官方Web部署工具,支持批量同步IIS配置:
- 先在一台模板服务器上配置好SSL绑定,再通过MSDeploy将配置同步至所有目标服务器
- 核心命令示例:
msdeploy.exe -verb:sync -source:webserver,computername=TemplateServer -dest:webserver,computername=TargetServer -enableRule:DoNotDeleteRule
3. IIS Administration API
- 官方REST API,可通过编程方式批量管理多台IIS服务器的SSL绑定,适合集成到现有自动化平台
内容的提问来源于stack exchange,提问作者samir patil
相关产品推荐
相关产品推荐

