重新签名PowerShell脚本遇未知错误,求解决方案
PowerShell脚本重新签名报错:No provider was specified for the store or object
问题描述
我从未在Windows 10或其他系统中创建过自签名证书,按步骤成功完成了证书创建与脚本签名。但修改脚本后重新签名时遇到问题,执行以下命令:
$codeCertificate = Get-ChildItem Cert:\LocalMachine\My | Where-Object {$_.Subject -eq "CN=ATA Authenticode"}
再执行:
Set-AuthenticodeSignature -FilePath C:\ATA\myscript.ps1 -Certificate $codeCertificate -TimeStampServer http://timestamp.digicert.com
收到UnknownError错误,提示信息为No provider was specified for the store or object.,未找到解决方案,寻求帮助。
解决方案
- 验证证书对象是否正确获取:执行
$codeCertificate,若返回多个结果或$null,说明筛选逻辑存在问题。建议改用证书指纹(Thumbprint)精准定位:# 列出本地机器个人存储中的证书,获取目标证书的Thumbprint Get-ChildItem Cert:\LocalMachine\My | Format-List Subject, Thumbprint # 通过Thumbprint获取证书 $codeCertificate = Get-ChildItem Cert:\LocalMachine\My\<替换为目标证书Thumbprint> - 确保以管理员权限运行PowerShell,访问
LocalMachine证书库需要管理员权限。 - 检查证书的代码签名有效性:确认证书未过期,且包含代码签名用途(OID: 1.3.6.1.5.5.7.3.3),执行以下命令验证:
$codeCertificate.EnhancedKeyUsageList - 尝试指定证书存储提供程序,修改证书获取命令:
$codeCertificate = Get-ChildItem Cert:\LocalMachine\My -Provider "Microsoft RSA SChannel Cryptographic Provider" | Where-Object {$_.Subject -eq "CN=ATA Authenticode"} - 若以上方法无效,直接用PowerShell重新创建代码签名证书:
New-SelfSignedCertificate -DnsName "ATA Authenticode" -CertStoreLocation Cert:\LocalMachine\My -Type CodeSigningCert
内容的提问来源于stack exchange,提问作者Ricardo Sanchez
相关产品推荐
相关产品推荐

