You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Win2012R2创建Azure兼容自签名证书遇Provider参数错误求助

在Windows Server 2012 R2域控上创建符合Azure要求的自签名证书问题

问题背景

刚接触Azure,需创建Azure应用用于脚本认证,该脚本连接Exchange Online(EXO3)收集客户所有Exchange通讯组。脚本本身可正常运行,但要在域控制器上作为计划任务执行,因此需要Azure认证。

证书上传失败

在域控制器上创建的基础自签名.cer证书因缺少Provider = 'Microsoft Enhanced RSA and AES Cryptographic Provider'属性,无法上传至Azure,上传提示:

Failed to add certificate. Error detail: Upload a certificate (public key) with one of the following types : .cer, .pem, .crt

证书为带密码的.cer格式,根据资料及微软文档,Azure要求证书必须具备该Provider属性。

PowerShell脚本报错

在Win2012R2域控制器上运行以下脚本时,PowerShell无法识别Provider参数:

$automationAccount = 'GetDistributionLists'   
$certExpiryMonths = 24  
$certPfxPassword = 'blahblah'  
$certExportPath = 'C:\'  
$resourceGroup = 'Name of Azure App'  
$location = "UK"  

$certPassword = ConvertTo-SecureString $certPfxPassword -AsPlainText -Force  

#Generate SSL certificate  
Write-Host "Generate self signed certificate for - $automationAccount"  
$selfSignedCertSplat = @{  
    DnsName = $automationAccount  
    Subject = $automationAccount  
    CertStoreLocation = 'cert:\CurrentUser\My'   
    KeyExportPolicy = 'Exportable'  
    Provider = 'Microsoft Enhanced RSA and AES Cryptographic Provider'  
    NotAfter = (Get-Date).AddMonths($certExpiryMonths)   
    HashAlgorithm = 'SHA256'  
}  
$selfSignedCert = New-SelfSignedCertificate @selfSignedCertSplat  

#Export SSL certificate to file  
Write-Host "Export self signed certificate to folder - $certExportPath"  
$certThumbPrint = 'cert:\CurrentUser\My\' + $selfSignedCert.Thumbprint  
Export-Certificate -Cert $certThumbPrint -FilePath "$certExportPath\$automationAccount.cer" -Type CERT | Write-Verbose

错误信息:

New-SelfSignedCertificate : A parameter cannot be found that matches parameter name 'Provider'.
At \\dfs\users\userfolders\username\Desktop\GetDistributionGroupCertAzure.ps1:22 char:45
+ $selfSignedCert = New-SelfSignedCertificate @selfSignedCertSplat
+                                             ~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidArgument: (:) [New-SelfSignedCertificate], ParameterBindingException
    + FullyQualifiedErrorId : NamedParameterNotFound,Microsoft.CertificateServices.Commands.NewSelfSignedCertificateCommand

当前环境

PowerShell版本:

Name                           Value                                                                                                                                         
----                           -----                                                                                                                                         
PSVersion                      5.1.14409.1029                                                                                                                                 
PSEdition                      Desktop                                                                                                                                        
PSCompatibleVersions           {1.0, 2.0, 3.0, 4.0...}                                                                                                                        
BuildVersion                   10.0.14409.1029                                                                                                                                
CLRVersion                     4.0.30319.42000                                                                                                                                
WSManStackVersion              3.0                                                                                                                                           
PSRemotingProtocolVersion      2.3                                                                                                                                           
SerializationVersion           1.1.0.1

疑问

原本以为需要在域控制器上创建证书(计划任务在此运行,这点可能有误),但看起来是PowerShell版本/模块限制导致问题。请问如何解决?是否可以在其他机器创建证书后导入域控制器使用?


解决方案

原因分析

Windows Server 2012 R2自带的New-SelfSignedCertificate cmdlet不支持Provider参数,该参数是Windows Server 2016及更高版本才引入的,这是导致脚本报错的直接原因。

方案1:在高版本Windows机器生成证书后导入域控制器

完全可以在其他支持Provider参数的机器(如Windows Server 2016/2019/2022、Windows 10/11)上生成符合要求的证书,再导入域控制器使用,步骤如下:

  1. 在高版本机器上运行你提供的脚本(保留Provider参数)生成证书
  2. 导出证书的PFX文件(包含私钥)和CER文件(公钥):
    # 导出PFX(带私钥)
    Export-PfxCertificate -Cert $selfSignedCert -FilePath "$certExportPath\$automationAccount.pfx" -Password $certPassword
    
  3. 将PFX文件导入到域控制器的证书存储:
    • 如果计划任务用本地系统账户运行,导入到LocalMachine\My
    • 如果用域用户账户运行,导入到该用户的CurrentUser\My
  4. 将CER文件上传到Azure AD应用的证书认证部分

方案2:在Windows Server 2012 R2上用makecert.exe生成证书

如果必须在域控制器上生成,可以使用makecert.exe工具(需安装Windows SDK)指定加密提供程序:

  1. 打开命令提示符,运行以下命令生成证书:
    makecert -r -pe -n "CN=GetDistributionLists" -b 01/01/2024 -e 01/01/2026 -eku 1.3.6.1.5.5.7.3.2 -ss my -sr CurrentUser -sky exchange -sp "Microsoft Enhanced RSA and AES Cryptographic Provider" -sy 24
    
    参数说明:
    • -r:创建自签名证书
    • -pe:标记私钥为可导出
    • -n:设置证书主题名称
    • -b/-e:指定证书的起始/到期日期
    • -eku:设置增强密钥用途(1.3.6.1.5.5.7.3.2代表客户端认证)
    • -ss/-sr:指定证书存储位置和范围
    • -sky:指定密钥类型为exchange
    • -sp:指定加密提供程序
    • -sy:提供程序类型代码(24对应目标提供程序)
  2. 用PowerShell导出CER文件:
    $cert = Get-ChildItem cert:\CurrentUser\My | Where-Object { $_.Subject -eq "CN=GetDistributionLists" }
    Export-Certificate -Cert $cert -FilePath "C:\GetDistributionLists.cer" -Type CERT
    

注意事项

  • 计划任务运行脚本时,要确保运行账户拥有证书私钥的访问权限
  • 上传到Azure的是CER格式的公钥,不需要密码;导入到域控制器的是PFX格式(含私钥),需用密码保护

内容的提问来源于stack exchange,提问作者Banjaxt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 15:10:05