You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何仅用PowerShell 5生成ca-cert.pem与client-cert.pem?

用PowerShell 5自动生成MySQL连接器所需的CA证书及客户端证书

我需要用PowerShell 5自动完成原本用OpenSSL手动生成ca-cert.pem和对应client-cert.pem的操作(这些证书用于PowerShell MySQL连接器),希望用最简单的方式实现;如果纯PowerShell做不到,可以借助轻量PowerShell模块。


原OpenSSL手动步骤

# 1. 创建CA密钥
openssl genrsa 2048 > ca-key.pem

# 2. 创建CA证书
openssl req -new -x509 -nodes -days 365000 -key ca-key.pem -out ca-cert.pem
# 需输入国家名称、州、地区名称等属性

# 3. 创建客户端证书请求
openssl req -newkey rsa:2048 -days 365000 -nodes -keyout client-key.pem -out client-req.pem
# 需输入与CA证书相同的属性

# 4. 清除客户端密钥的保护密码
openssl rsa -in client-key.pem -out client-key.pem

# 5. 签发客户端证书
openssl x509 -req -in client-req.pem -days 365000 -CA ca-cert.pem -CAkey ca-key.pem -set_serial 01 -out client-cert.pem

我当前的尝试(与需求差距较大)

我目前只能用以下代码创建自签名证书并导出.cer和.pfx文件,但这和需要的.pem证书结构不符:

$cert = New-SelfSignedCertificate -DnsName "CN=MyCert" -CertStoreLocation "Cert:\CurrentUser\My" -KeyLength 2048 -KeyAlgorithm "RSA" -KeyExportPolicy Exportable 

Export-Certificate -Cert $cert -FilePath "C:\temp\MyCert.cer"

$cert | Export-PfxCertificate -FilePath "C:\temp\MyCert.pfx" -Password (ConvertTo-SecureString -String "password" -AsPlainText -Force)

最简PowerShell实现方案

方案1:纯PowerShell 5+系统工具实现

依赖系统自带的certutil和OpenSSL(若系统未预装,可下载轻量版放到系统PATH中),无需额外模块:

# 定义输出路径与证书属性
$outputPath = "C:\temp"
$caSubject = "CN=MySQL-CA, O=MyOrg, C=CN, ST=Shanghai, L=Pudong"
$clientSubject = "CN=MySQL-Client, O=MyOrg, C=CN, ST=Shanghai, L=Pudong"
$validityDays = 365000

# 创建自签名CA证书
$caCert = New-SelfSignedCertificate `
    -Subject $caSubject `
    -CertStoreLocation "Cert:\CurrentUser\My" `
    -KeyLength 2048 `
    -KeyAlgorithm RSA `
    -KeyExportPolicy Exportable `
    -KeyUsage CertSign, CRLSign, DigitalSignature `
    -Type Custom `
    -NotAfter (Get-Date).AddDays($validityDays)

# 创建由CA签发的客户端证书
$clientCert = New-SelfSignedCertificate `
    -Subject $clientSubject `
    -CertStoreLocation "Cert:\CurrentUser\My" `
    -KeyLength 2048 `
    -KeyAlgorithm RSA `
    -KeyExportPolicy Exportable `
    -Signer $caCert `
    -NotAfter (Get-Date).AddDays($validityDays)

# 导出CA证书为PEM格式
$caCerPath = Join-Path $outputPath "ca-cert.cer"
$caCert | Export-Certificate -FilePath $caCerPath -Type CERT
certutil -encode $caCerPath (Join-Path $outputPath "ca-cert.pem")
Remove-Item $caCerPath

# 导出客户端证书为PEM格式
$clientCerPath = Join-Path $outputPath "client-cert.cer"
$clientCert | Export-Certificate -FilePath $clientCerPath -Type CERT
certutil -encode $clientCerPath (Join-Path $outputPath "client-cert.pem")
Remove-Item $clientCerPath

# 导出客户端密钥为无密码PEM
$tempPfx = Join-Path $outputPath "temp-client.pfx"
$clientCert | Export-PfxCertificate -FilePath $tempPfx -Password (ConvertTo-SecureString "" -AsPlainText -Force)
openssl pkcs12 -in $tempPfx -nocerts -nodes -out (Join-Path $outputPath "client-key.pem")
Remove-Item $tempPfx

# 导出CA密钥为无密码PEM
$tempCaPfx = Join-Path $outputPath "temp-ca.pfx"
$caCert | Export-PfxCertificate -FilePath $tempCaPfx -Password (ConvertTo-SecureString "" -AsPlainText -Force)
openssl pkcs12 -in $tempCaPfx -nocerts -nodes -out (Join-Path $outputPath "ca-key.pem")
Remove-Item $tempCaPfx

# 清理证书存储中的临时证书(可选)
Remove-Item $caCert.PSPath
Remove-Item $clientCert.PSPath

方案2:借助轻量PowerShell模块PSScriptTools

若不想依赖OpenSSL,可使用微软认证的轻量模块PSScriptTools完成纯PowerShell转换:

# 安装模块(仅需执行一次)
Install-Module -Name PSScriptTools -Scope CurrentUser -Force

# 定义参数
$outputPath = "C:\temp"
$caSubject = "CN=MySQL-CA, O=MyOrg, C=CN, ST=Shanghai, L=Pudong"
$clientSubject = "CN=MySQL-Client, O=MyOrg, C=CN, ST=Shanghai, L=Pudong"
$validityDays = 365000

# 创建CA证书
$caCert = New-SelfSignedCertificate `
    -Subject $caSubject `
    -CertStoreLocation "Cert:\CurrentUser\My" `
    -KeyLength 2048 `
    -KeyAlgorithm RSA `
    -KeyExportPolicy Exportable `
    -KeyUsage CertSign, CRLSign, DigitalSignature `
    -Type Custom `
    -NotAfter (Get-Date).AddDays($validityDays)

# 创建客户端证书(由CA签发)
$clientCert = New-SelfSignedCertificate `
    -Subject $clientSubject `
    -CertStoreLocation "Cert:\CurrentUser\My" `
    -KeyLength 2048 `
    -KeyAlgorithm RSA `
    -KeyExportPolicy Exportable `
    -Signer $caCert `
    -NotAfter (Get-Date).AddDays($validityDays)

# 导出CA证书为PEM
$caCerPath = Join-Path $outputPath "ca-cert.cer"
Export-Certificate -Cert $caCert -FilePath $caCerPath
ConvertTo-Pem -Path $caCerPath -OutputFilePath (Join-Path $outputPath "ca-cert.pem")
Remove-Item $caCerPath

# 导出客户端证书为PEM
$clientCerPath = Join-Path $outputPath "client-cert.cer"
Export-Certificate -Cert $clientCert -FilePath $clientCerPath
ConvertTo-Pem -Path $clientCerPath -OutputFilePath (Join-Path $outputPath "client-cert.pem")
Remove-Item $clientCerPath

# 导出客户端密钥为无密码PEM
$clientKey = Get-Item $clientCert.PrivateKey
$clientKeyPem = ConvertTo-Pem -PrivateKey $clientKey
$clientKeyPem | Out-File (Join-Path $outputPath "client-key.pem") -Encoding Ascii

# 导出CA密钥为无密码PEM
$caKey = Get-Item $caCert.PrivateKey
$caKeyPem = ConvertTo-Pem -PrivateKey $caKey
$caKeyPem | Out-File (Join-Path $outputPath "ca-key.pem") -Encoding Ascii

# 清理临时证书
Remove-Item $caCert.PSPath
Remove-Item $clientCert.PSPath

内容的提问来源于stack exchange,提问作者MKANET

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 17:31:00