You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Point-to-Site:能否从Key Vault读取公证书数据而非明文存储?

Azure Point-to-Site 能否从Key Vault读取公证书?

可以实现从Azure Key Vault读取公证书来配置Point-to-Site(P2S)VPN,无需将公证书明文存储在P2S配置区域。不过Azure门户的手动配置界面不支持直接引用Key Vault证书,需要通过自动化工具完成:

  • 权限准备:

    • 确保VPN网关与Key Vault处于同一订阅内。
    • 为VPN网关的托管标识(系统分配或用户分配)分配Key Vault的Certificate Get权限,让网关能够读取证书数据。
  • 使用Azure CLI配置:
    直接通过CLI命令引用Key Vault中的证书,无需手动提取明文:

    az network vnet-gateway vpn-client root-cert add \
      --gateway-name <你的VPN网关名称> \
      --resource-group <资源组名称> \
      --certificate-name <Key Vault中的证书名称> \
      --key-vault <Key Vault名称>
    
  • 使用PowerShell配置:
    先从Key Vault获取证书数据,再传入P2S配置:

    # 从Key Vault获取证书
    $kvCert = Get-AzKeyVaultCertificate -VaultName "<Key Vault名称>" -Name "<证书名称>"
    # 将证书数据添加到P2S配置
    Add-AzVpnClientRootCertificate -VpnClientRootCertificateName "<证书显示名称>" `
      -VirtualNetworkGatewayName "<VPN网关名称>" `
      -ResourceGroupName "<资源组名称>" `
      -PublicCertData $kvCert.Cer
    
  • 使用ARM模板配置:
    在ARM模板中直接引用Key Vault的证书资源ID,部署时自动拉取证书数据完成配置,示例片段:

    "properties": {
      "vpnClientConfiguration": {
        "vpnClientRootCertificates": [
          {
            "name": "<证书显示名称>",
            "properties": {
              "publicCertData": "[reference(resourceId('<Key Vault资源组>', 'Microsoft.KeyVault/vaults/certificates', '<Key Vault名称>', '<证书名称>'), '2023-02-01').cer]"
            }
          }
        ]
      }
    }
    

这种方式既避免了明文存储公证书的风险,也能借助Key Vault实现证书的集中管理、自动轮换等功能。

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 19:05:22