Docker中Windows Server实例SSL证书安装绑定问题排查
Docker容器中经典ASP站点SSL证书安装问题
在Docker容器中运行经典ASP站点时,安装SSL证书遇到以下问题:
可行方案
使用以下PowerShell命令可成功安装并绑定PFX证书:
$pwd = ConvertTo-SecureString -String "password" -AsPlainText -Force $cert = Import-PfxCertificate -Password $pwd -FilePath "c:\cert\cert.pfx" -CertStoreLocation Cert:\LocalMachine\My #-Exportable # optional if i want the private key to be exportable New-IISSiteBinding -Name MySite -BindingInformation "*:443:sub.mydomain.com" -CertificateThumbPrint $cert.Thumbprint -CertStoreLocation "cert:\LocalMachine\my" -Protocol "https"
但该方案存在私钥及密码安全难以保障的问题,暂不考虑。
不可行方案
安装从Digicert下载的cer/crt证书时,执行以下命令可成功完成导入:
$cert = Import-Certificate -FilePath C:\cert\mycert.cer -CertStoreLocation Cert:\LocalMachine\My\
但执行站点绑定命令时持续报错:
New-IISSiteBinding : A specified logon session does not exist. It may already have been terminated. (Exception from HRESULT: 0x80070520) At line:1 char:1 + New-IISSiteBinding -Name MySite -BindingInformation "*:443:at ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : NotSpecified: (:) [New-IISSiteBinding], COMException + FullyQualifiedErrorId : System.Runtime.InteropServices.COMException,Microsoft.IIS.Powershell.Commands.NewIISSiteBindingCommand
推测是权限问题,但仅能通过终端操作Docker容器,无法在cert:\LocalMachine\My路径执行Get-Acl查看权限。
疑问
- 该报错是否为权限问题?
- 物理证书存储位置在哪,以便授予权限?
- 容器中IIS运行的用户身份是什么?
内容的提问来源于stack exchange,提问作者Jay
相关产品推荐
相关产品推荐

