Win2012R2创建Azure兼容自签名证书遇Provider参数错误求助
问题背景
刚接触Azure,需创建Azure应用用于脚本认证,该脚本连接Exchange Online(EXO3)收集客户所有Exchange通讯组。脚本本身可正常运行,但要在域控制器上作为计划任务执行,因此需要Azure认证。
证书上传失败
在域控制器上创建的基础自签名.cer证书因缺少Provider = 'Microsoft Enhanced RSA and AES Cryptographic Provider'属性,无法上传至Azure,上传提示:
Failed to add certificate. Error detail: Upload a certificate (public key) with one of the following types : .cer, .pem, .crt
证书为带密码的.cer格式,根据资料及微软文档,Azure要求证书必须具备该Provider属性。
PowerShell脚本报错
在Win2012R2域控制器上运行以下脚本时,PowerShell无法识别Provider参数:
$automationAccount = 'GetDistributionLists' $certExpiryMonths = 24 $certPfxPassword = 'blahblah' $certExportPath = 'C:\' $resourceGroup = 'Name of Azure App' $location = "UK" $certPassword = ConvertTo-SecureString $certPfxPassword -AsPlainText -Force #Generate SSL certificate Write-Host "Generate self signed certificate for - $automationAccount" $selfSignedCertSplat = @{ DnsName = $automationAccount Subject = $automationAccount CertStoreLocation = 'cert:\CurrentUser\My' KeyExportPolicy = 'Exportable' Provider = 'Microsoft Enhanced RSA and AES Cryptographic Provider' NotAfter = (Get-Date).AddMonths($certExpiryMonths) HashAlgorithm = 'SHA256' } $selfSignedCert = New-SelfSignedCertificate @selfSignedCertSplat #Export SSL certificate to file Write-Host "Export self signed certificate to folder - $certExportPath" $certThumbPrint = 'cert:\CurrentUser\My\' + $selfSignedCert.Thumbprint Export-Certificate -Cert $certThumbPrint -FilePath "$certExportPath\$automationAccount.cer" -Type CERT | Write-Verbose
错误信息:
New-SelfSignedCertificate : A parameter cannot be found that matches parameter name 'Provider'. At \\dfs\users\userfolders\username\Desktop\GetDistributionGroupCertAzure.ps1:22 char:45 + $selfSignedCert = New-SelfSignedCertificate @selfSignedCertSplat + ~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : InvalidArgument: (:) [New-SelfSignedCertificate], ParameterBindingException + FullyQualifiedErrorId : NamedParameterNotFound,Microsoft.CertificateServices.Commands.NewSelfSignedCertificateCommand
当前环境
PowerShell版本:
Name Value ---- ----- PSVersion 5.1.14409.1029 PSEdition Desktop PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...} BuildVersion 10.0.14409.1029 CLRVersion 4.0.30319.42000 WSManStackVersion 3.0 PSRemotingProtocolVersion 2.3 SerializationVersion 1.1.0.1
疑问
原本以为需要在域控制器上创建证书(计划任务在此运行,这点可能有误),但看起来是PowerShell版本/模块限制导致问题。请问如何解决?是否可以在其他机器创建证书后导入域控制器使用?
解决方案
原因分析
Windows Server 2012 R2自带的New-SelfSignedCertificate cmdlet不支持Provider参数,该参数是Windows Server 2016及更高版本才引入的,这是导致脚本报错的直接原因。
方案1:在高版本Windows机器生成证书后导入域控制器
完全可以在其他支持Provider参数的机器(如Windows Server 2016/2019/2022、Windows 10/11)上生成符合要求的证书,再导入域控制器使用,步骤如下:
- 在高版本机器上运行你提供的脚本(保留
Provider参数)生成证书 - 导出证书的PFX文件(包含私钥)和CER文件(公钥):
# 导出PFX(带私钥) Export-PfxCertificate -Cert $selfSignedCert -FilePath "$certExportPath\$automationAccount.pfx" -Password $certPassword - 将PFX文件导入到域控制器的证书存储:
- 如果计划任务用本地系统账户运行,导入到
LocalMachine\My - 如果用域用户账户运行,导入到该用户的
CurrentUser\My
- 如果计划任务用本地系统账户运行,导入到
- 将CER文件上传到Azure AD应用的证书认证部分
方案2:在Windows Server 2012 R2上用makecert.exe生成证书
如果必须在域控制器上生成,可以使用makecert.exe工具(需安装Windows SDK)指定加密提供程序:
- 打开命令提示符,运行以下命令生成证书:
参数说明:makecert -r -pe -n "CN=GetDistributionLists" -b 01/01/2024 -e 01/01/2026 -eku 1.3.6.1.5.5.7.3.2 -ss my -sr CurrentUser -sky exchange -sp "Microsoft Enhanced RSA and AES Cryptographic Provider" -sy 24-r:创建自签名证书-pe:标记私钥为可导出-n:设置证书主题名称-b/-e:指定证书的起始/到期日期-eku:设置增强密钥用途(1.3.6.1.5.5.7.3.2代表客户端认证)-ss/-sr:指定证书存储位置和范围-sky:指定密钥类型为exchange-sp:指定加密提供程序-sy:提供程序类型代码(24对应目标提供程序)
- 用PowerShell导出CER文件:
$cert = Get-ChildItem cert:\CurrentUser\My | Where-Object { $_.Subject -eq "CN=GetDistributionLists" } Export-Certificate -Cert $cert -FilePath "C:\GetDistributionLists.cer" -Type CERT
注意事项
- 计划任务运行脚本时,要确保运行账户拥有证书私钥的访问权限
- 上传到Azure的是CER格式的公钥,不需要密码;导入到域控制器的是PFX格式(含私钥),需用密码保护
内容的提问来源于stack exchange,提问作者Banjaxt

