You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell生成代码签名证书时遇OID错误0x80070057求助

解决New-SelfSignedCertificate生成代码签名证书的OID参数错误问题

问题描述

使用PowerShell 7.2.9的New-SelfSignedCertificate命令生成开发用自签名代码签名证书时,出现以下OID错误:

Invalid extension specified: 2.5.29.37.3={text}1.3.6.1.5.5.7.3.3:
CertEnroll::CX509Extension::_InitializeFromString: 2.5.29.37.3={text}1.3.6.1.5.5.7.3.3: The parameter is incorrect.
0x80070057 (WIN32: 87 ERROR_INVALID_PARAMETER)

确认使用的扩展OID对应代码签名用途,但仍报错。附上根证书与代码签名证书的生成代码:

#Included the Root Cert's generation code too incase there's an issue with it
#that breaks the code signing cert, when using the Root to sign the child cert.

$relativeDistinguishedName = ", OU=ABC, OU=DEF, OU=GHI, O=JKL, L=MNO, ST=MA, C=US"
$rootFriendlyName = "ABC - DEV Root CA"
$codeSigningFriendlyName = "ABC - DEV Code Signing"

Function GetRootCA(){
    #Retrieve appropraite root CA to sign this certificate
    $rootCA = Get-ChildItem -Path "Cert:\LocalMachine\My" -Recurse | 
        Where-Object {$_.FriendlyName -eq $rootFriendlyName}
    
    return $rootCA
}

function GenerateRootCA() {
    $rootCA = GetRootCA
    if($rootCA -ne $null){
        " "
        Write-Host "Trusted root certificate located."
        $rootCA | Format-List -Property *
        return
    }

    Write-Host "Generating root CA certificate." -ForegroundColor Yellow

    $certSub = -Join("CN=ABC Dev - Root CA", $relativeDistinguishedName)

    $certParms = @{
        Type = "Custom"
        CertStoreLocation = "Cert:\LocalMachine\My"     
        Subject = $certSub
        FriendlyName = $rootFriendlyName
        NotAfter = (Get-Date).AddYears(2)
        KeyExportPolicy = "NonExportable"
        KeyDescription = "A development network root certificate authority for creating trusted development certificates."
        KeySpec = "Signature"
        KeyUsage = "None"
        KeyUsageProperty = "All"
    }
    $cert = New-SelfSignedCertificate @certParms
    $cert | Format-List -Property *
}

function GenerateCodeSigning() {    
    $rootCA = GetRootCA
    if($rootCA -eq $null){
        Write-Host "No trusted root certificate located!" -ForegroundColor Red
        return
    }

    $certSub = -Join("CN=ABC Dev - Code Signing", $relativeDistinguishedName)

    $certParms = @{
        Type = "CodeSigningCert"
        CertStoreLocation = "Cert:\LocalMachine\My"
        Subject = $certSub
        FriendlyName = $codeSigningFriendlyName
        NotAfter = (Get-Date).AddYears(2)
        KeyExportPolicy = "Exportable"
        KeyDescription = "A development network code signing certificate for ABC applications."
        KeyAlgorithm = "RSA"
        KeyLength = 2048
        HashAlgorithm = "SHA256"
        Provider = "Microsoft Enhanced RSA and AES Cryptographic Provider"
        Signer = $rootCA    
        KeySpec = "Signature"
        KeyUsage = @("DigitalSignature")
        TextExtension = @("2.5.29.37.3={text}1.3.6.1.5.5.7.3.3")
    }

    $cert = New-SelfSignedCertificate @certParms
    $cert | Format-List -Property *
}

解决方案

错误根源是TextExtension参数的格式错误:

  • 2.5.29.37.3是**增强密钥用法(EKU)**扩展,该扩展的值需要用{oid}格式而非{text}格式来指定OID。
  • 另外,你已经指定了Type = "CodeSigningCert",这个参数会自动为证书添加代码签名的EKU(1.3.6.1.5.5.7.3.3),手动添加TextExtension属于重复操作,反而引发格式冲突。

修复方法二选一:

  1. 移除多余的TextExtension参数(推荐)
    修改GenerateCodeSigning函数中的certParms,删掉TextExtension这一行即可:

    $certParms = @{
        Type = "CodeSigningCert"
        CertStoreLocation = "Cert:\LocalMachine\My"
        Subject = $certSub
        FriendlyName = $codeSigningFriendlyName
        NotAfter = (Get-Date).AddYears(2)
        KeyExportPolicy = "Exportable"
        KeyDescription = "A development network code signing certificate for ABC applications."
        KeyAlgorithm = "RSA"
        KeyLength = 2048
        HashAlgorithm = "SHA256"
        Provider = "Microsoft Enhanced RSA and AES Cryptographic Provider"
        Signer = $rootCA    
        KeySpec = "Signature"
        KeyUsage = @("DigitalSignature")
    }
    
  2. 修正TextExtension的格式(若需手动指定EKU)
    如果你确实需要手动定义EKU扩展,将{text}替换为{oid}:

    TextExtension = @("2.5.29.37.3={oid}1.3.6.1.5.5.7.3.3")
    

执行修正后的代码即可正常生成代码签名证书。

内容的提问来源于stack exchange,提问作者Reahreic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 20:23:18