You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:如何通过PowerShell脚本为IIS网站绑定已有SSL证书

IIS绑定已有SSL证书的PowerShell自动化脚本

完整可运行脚本

以下是能解决你问题的自动化步骤,替代你之前的尝试:

  1. 定位目标证书
    可以通过证书主题或指纹精准找到要绑定的证书:
# 方式1:通过证书主题筛选(替换为你的证书主题,比如"CN=yourdomain.com")
$certSubject = "CN=yourdomain.com"
$cert = Get-ChildItem -Path Cert:\LocalMachine\My | Where-Object {$_.Subject -eq $certSubject}

# 方式2:通过证书指纹筛选(替换为你的证书指纹,注意去掉空格)
# $certThumbprint = "ABC123DEF456GHI789JKL012MNOP345QRST678UVW"
# $cert = Get-ChildItem -Path Cert:\LocalMachine\My | Where-Object {$_.Thumbprint -eq $certThumbprint}
  1. 创建HTTPS绑定(自动检查是否已存在)
$siteName = "Default Web Site"
$port = 443
$ipAddress = "*"
$hostHeader = "" # 若需绑定特定域名,填写如"yourdomain.com"

# 避免重复创建绑定
$existingBinding = Get-WebBinding -Name $siteName -Protocol https | Where-Object {
    $_.EndPoint.Port -eq $port -and $_.EndPoint.Address.ToString() -eq $ipAddress -and $_.HostHeader -eq $hostHeader
}

if (-not $existingBinding) {
    New-WebBinding -Name $siteName -IP $ipAddress -Port $port -Protocol https -HostHeader $hostHeader
}
  1. 关联证书到绑定(关键步骤)
    之前的方法未关联到指定网站,用netsh命令完成证书与绑定的关联:
# 用IIS默认GUID即可,无需修改
$appId = "{4dc3e181-e14b-4a21-b022-59fc669b0914}"
netsh http add sslcert ipport="$ipAddress`:$port" certhash=$cert.Thumbprint appid=$appId

若绑定了主机头(SNI),需在netsh命令中追加hostname=$hostHeader参数

排查要点

  • 必须以管理员身份运行PowerShell,否则无权限修改IIS和HTTP配置
  • 确保证书已导入LocalMachine\My(个人存储)且带有私钥
  • 若提示证书已绑定,可先用netsh http delete sslcert ipport="$ipAddress:$port"`删除旧绑定后重试

内容的提问来源于stack exchange,提问作者prabhat Saraswat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 00:22:10