You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Bicep在Azure Key Vault中生成证书?

使用Bicep在Azure Key Vault中创建独立证书

你需要使用Microsoft.KeyVault/vaults/certificates资源类型来在Key Vault中生成证书,而不是Microsoft.Web/certificates(后者是用于App Service的托管证书,必须绑定服务,不符合你的需求)。

完整Bicep示例

下面的代码会在已存在的Key Vault中创建一张自签名证书:

// 定义参数
param keyVaultName string
param certificateName string = 'mySelfSignedCert'
param certSubject string = 'CN=example.com'
param certValidityMonths int = 12

// 引用已有的Key Vault
resource keyVault 'Microsoft.KeyVault/vaults@2023-07-01' existing = {
  name: keyVaultName
}

// 在Key Vault中创建证书
resource kvCertificate 'Microsoft.KeyVault/vaults/certificates@2023-07-01' = {
  parent: keyVault
  name: certificateName
  properties: {
    certificatePolicy: {
      // 配置自签名 issuer
      issuerParameters: {
        name: 'Self'
      }
      // 密钥相关配置
      keyProperties: {
        exportable: true
        keySize: 2048
        keyType: 'RSA'
        reuseKey: true
      }
      // 密钥保管库中存储证书的格式
      secretProperties: {
        contentType: 'application/x-pkcs12'
      }
      // X.509证书属性
      x509CertificateProperties: {
        subject: certSubject
        validityInMonths: certValidityMonths
        keyUsage: [
          'digitalSignature'
          'keyEncipherment'
        ]
      }
    }
  }
}

关键配置说明

  • 资源关联:通过parent属性将证书资源绑定到目标Key Vault,确保证书创建在指定的密钥保管库内。
  • Issuer配置:issuerParameters.name设为Self表示生成自签名证书;如果需要使用第三方CA(如DigiCert),需先在Key Vault中配置对应的CA集成,再替换此处的 issuer 名称。
  • 密钥属性:exportable: true允许后续导出证书私钥,可根据实际需求调整。

部署命令

使用Azure CLI部署该Bicep文件:

az deployment group create --resource-group <你的资源组名> --template-file <bicep文件路径> --parameters keyVaultName=<你的Key Vault名称>

内容的提问来源于stack exchange,提问作者Marko

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 23:00:12