使用PowerShell生成代码签名证书时遇OID错误0x80070057求助
解决New-SelfSignedCertificate生成代码签名证书的OID参数错误问题
问题描述
使用PowerShell 7.2.9的New-SelfSignedCertificate命令生成开发用自签名代码签名证书时,出现以下OID错误:
Invalid extension specified: 2.5.29.37.3={text}1.3.6.1.5.5.7.3.3: CertEnroll::CX509Extension::_InitializeFromString: 2.5.29.37.3={text}1.3.6.1.5.5.7.3.3: The parameter is incorrect. 0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)
确认使用的扩展OID对应代码签名用途,但仍报错。附上根证书与代码签名证书的生成代码:
#Included the Root Cert's generation code too incase there's an issue with it #that breaks the code signing cert, when using the Root to sign the child cert. $relativeDistinguishedName = ", OU=ABC, OU=DEF, OU=GHI, O=JKL, L=MNO, ST=MA, C=US" $rootFriendlyName = "ABC - DEV Root CA" $codeSigningFriendlyName = "ABC - DEV Code Signing" Function GetRootCA(){ #Retrieve appropraite root CA to sign this certificate $rootCA = Get-ChildItem -Path "Cert:\LocalMachine\My" -Recurse | Where-Object {$_.FriendlyName -eq $rootFriendlyName} return $rootCA } function GenerateRootCA() { $rootCA = GetRootCA if($rootCA -ne $null){ " " Write-Host "Trusted root certificate located." $rootCA | Format-List -Property * return } Write-Host "Generating root CA certificate." -ForegroundColor Yellow $certSub = -Join("CN=ABC Dev - Root CA", $relativeDistinguishedName) $certParms = @{ Type = "Custom" CertStoreLocation = "Cert:\LocalMachine\My" Subject = $certSub FriendlyName = $rootFriendlyName NotAfter = (Get-Date).AddYears(2) KeyExportPolicy = "NonExportable" KeyDescription = "A development network root certificate authority for creating trusted development certificates." KeySpec = "Signature" KeyUsage = "None" KeyUsageProperty = "All" } $cert = New-SelfSignedCertificate @certParms $cert | Format-List -Property * } function GenerateCodeSigning() { $rootCA = GetRootCA if($rootCA -eq $null){ Write-Host "No trusted root certificate located!" -ForegroundColor Red return } $certSub = -Join("CN=ABC Dev - Code Signing", $relativeDistinguishedName) $certParms = @{ Type = "CodeSigningCert" CertStoreLocation = "Cert:\LocalMachine\My" Subject = $certSub FriendlyName = $codeSigningFriendlyName NotAfter = (Get-Date).AddYears(2) KeyExportPolicy = "Exportable" KeyDescription = "A development network code signing certificate for ABC applications." KeyAlgorithm = "RSA" KeyLength = 2048 HashAlgorithm = "SHA256" Provider = "Microsoft Enhanced RSA and AES Cryptographic Provider" Signer = $rootCA KeySpec = "Signature" KeyUsage = @("DigitalSignature") TextExtension = @("2.5.29.37.3={text}1.3.6.1.5.5.7.3.3") } $cert = New-SelfSignedCertificate @certParms $cert | Format-List -Property * }
解决方案
错误根源是TextExtension参数的格式错误:
- 2.5.29.37.3是**增强密钥用法(EKU)**扩展,该扩展的值需要用
{oid}格式而非{text}格式来指定OID。 - 另外,你已经指定了
Type = "CodeSigningCert",这个参数会自动为证书添加代码签名的EKU(1.3.6.1.5.5.7.3.3),手动添加TextExtension属于重复操作,反而引发格式冲突。
修复方法二选一:
移除多余的TextExtension参数(推荐)
修改GenerateCodeSigning函数中的certParms,删掉TextExtension这一行即可:$certParms = @{ Type = "CodeSigningCert" CertStoreLocation = "Cert:\LocalMachine\My" Subject = $certSub FriendlyName = $codeSigningFriendlyName NotAfter = (Get-Date).AddYears(2) KeyExportPolicy = "Exportable" KeyDescription = "A development network code signing certificate for ABC applications." KeyAlgorithm = "RSA" KeyLength = 2048 HashAlgorithm = "SHA256" Provider = "Microsoft Enhanced RSA and AES Cryptographic Provider" Signer = $rootCA KeySpec = "Signature" KeyUsage = @("DigitalSignature") }修正TextExtension的格式(若需手动指定EKU)
如果你确实需要手动定义EKU扩展,将{text}替换为{oid}:TextExtension = @("2.5.29.37.3={oid}1.3.6.1.5.5.7.3.3")
执行修正后的代码即可正常生成代码签名证书。
内容的提问来源于stack exchange,提问作者Reahreic
相关产品推荐
相关产品推荐

