如何仅用PowerShell 5生成ca-cert.pem与client-cert.pem?
用PowerShell 5自动生成MySQL连接器所需的CA证书及客户端证书
我需要用PowerShell 5自动完成原本用OpenSSL手动生成ca-cert.pem和对应client-cert.pem的操作(这些证书用于PowerShell MySQL连接器),希望用最简单的方式实现;如果纯PowerShell做不到,可以借助轻量PowerShell模块。
原OpenSSL手动步骤
# 1. 创建CA密钥 openssl genrsa 2048 > ca-key.pem # 2. 创建CA证书 openssl req -new -x509 -nodes -days 365000 -key ca-key.pem -out ca-cert.pem # 需输入国家名称、州、地区名称等属性 # 3. 创建客户端证书请求 openssl req -newkey rsa:2048 -days 365000 -nodes -keyout client-key.pem -out client-req.pem # 需输入与CA证书相同的属性 # 4. 清除客户端密钥的保护密码 openssl rsa -in client-key.pem -out client-key.pem # 5. 签发客户端证书 openssl x509 -req -in client-req.pem -days 365000 -CA ca-cert.pem -CAkey ca-key.pem -set_serial 01 -out client-cert.pem
我当前的尝试(与需求差距较大)
我目前只能用以下代码创建自签名证书并导出.cer和.pfx文件,但这和需要的.pem证书结构不符:
$cert = New-SelfSignedCertificate -DnsName "CN=MyCert" -CertStoreLocation "Cert:\CurrentUser\My" -KeyLength 2048 -KeyAlgorithm "RSA" -KeyExportPolicy Exportable Export-Certificate -Cert $cert -FilePath "C:\temp\MyCert.cer" $cert | Export-PfxCertificate -FilePath "C:\temp\MyCert.pfx" -Password (ConvertTo-SecureString -String "password" -AsPlainText -Force)
最简PowerShell实现方案
方案1:纯PowerShell 5+系统工具实现
依赖系统自带的certutil和OpenSSL(若系统未预装,可下载轻量版放到系统PATH中),无需额外模块:
# 定义输出路径与证书属性 $outputPath = "C:\temp" $caSubject = "CN=MySQL-CA, O=MyOrg, C=CN, ST=Shanghai, L=Pudong" $clientSubject = "CN=MySQL-Client, O=MyOrg, C=CN, ST=Shanghai, L=Pudong" $validityDays = 365000 # 创建自签名CA证书 $caCert = New-SelfSignedCertificate ` -Subject $caSubject ` -CertStoreLocation "Cert:\CurrentUser\My" ` -KeyLength 2048 ` -KeyAlgorithm RSA ` -KeyExportPolicy Exportable ` -KeyUsage CertSign, CRLSign, DigitalSignature ` -Type Custom ` -NotAfter (Get-Date).AddDays($validityDays) # 创建由CA签发的客户端证书 $clientCert = New-SelfSignedCertificate ` -Subject $clientSubject ` -CertStoreLocation "Cert:\CurrentUser\My" ` -KeyLength 2048 ` -KeyAlgorithm RSA ` -KeyExportPolicy Exportable ` -Signer $caCert ` -NotAfter (Get-Date).AddDays($validityDays) # 导出CA证书为PEM格式 $caCerPath = Join-Path $outputPath "ca-cert.cer" $caCert | Export-Certificate -FilePath $caCerPath -Type CERT certutil -encode $caCerPath (Join-Path $outputPath "ca-cert.pem") Remove-Item $caCerPath # 导出客户端证书为PEM格式 $clientCerPath = Join-Path $outputPath "client-cert.cer" $clientCert | Export-Certificate -FilePath $clientCerPath -Type CERT certutil -encode $clientCerPath (Join-Path $outputPath "client-cert.pem") Remove-Item $clientCerPath # 导出客户端密钥为无密码PEM $tempPfx = Join-Path $outputPath "temp-client.pfx" $clientCert | Export-PfxCertificate -FilePath $tempPfx -Password (ConvertTo-SecureString "" -AsPlainText -Force) openssl pkcs12 -in $tempPfx -nocerts -nodes -out (Join-Path $outputPath "client-key.pem") Remove-Item $tempPfx # 导出CA密钥为无密码PEM $tempCaPfx = Join-Path $outputPath "temp-ca.pfx" $caCert | Export-PfxCertificate -FilePath $tempCaPfx -Password (ConvertTo-SecureString "" -AsPlainText -Force) openssl pkcs12 -in $tempCaPfx -nocerts -nodes -out (Join-Path $outputPath "ca-key.pem") Remove-Item $tempCaPfx # 清理证书存储中的临时证书(可选) Remove-Item $caCert.PSPath Remove-Item $clientCert.PSPath
方案2:借助轻量PowerShell模块PSScriptTools
若不想依赖OpenSSL,可使用微软认证的轻量模块PSScriptTools完成纯PowerShell转换:
# 安装模块(仅需执行一次) Install-Module -Name PSScriptTools -Scope CurrentUser -Force # 定义参数 $outputPath = "C:\temp" $caSubject = "CN=MySQL-CA, O=MyOrg, C=CN, ST=Shanghai, L=Pudong" $clientSubject = "CN=MySQL-Client, O=MyOrg, C=CN, ST=Shanghai, L=Pudong" $validityDays = 365000 # 创建CA证书 $caCert = New-SelfSignedCertificate ` -Subject $caSubject ` -CertStoreLocation "Cert:\CurrentUser\My" ` -KeyLength 2048 ` -KeyAlgorithm RSA ` -KeyExportPolicy Exportable ` -KeyUsage CertSign, CRLSign, DigitalSignature ` -Type Custom ` -NotAfter (Get-Date).AddDays($validityDays) # 创建客户端证书(由CA签发) $clientCert = New-SelfSignedCertificate ` -Subject $clientSubject ` -CertStoreLocation "Cert:\CurrentUser\My" ` -KeyLength 2048 ` -KeyAlgorithm RSA ` -KeyExportPolicy Exportable ` -Signer $caCert ` -NotAfter (Get-Date).AddDays($validityDays) # 导出CA证书为PEM $caCerPath = Join-Path $outputPath "ca-cert.cer" Export-Certificate -Cert $caCert -FilePath $caCerPath ConvertTo-Pem -Path $caCerPath -OutputFilePath (Join-Path $outputPath "ca-cert.pem") Remove-Item $caCerPath # 导出客户端证书为PEM $clientCerPath = Join-Path $outputPath "client-cert.cer" Export-Certificate -Cert $clientCert -FilePath $clientCerPath ConvertTo-Pem -Path $clientCerPath -OutputFilePath (Join-Path $outputPath "client-cert.pem") Remove-Item $clientCerPath # 导出客户端密钥为无密码PEM $clientKey = Get-Item $clientCert.PrivateKey $clientKeyPem = ConvertTo-Pem -PrivateKey $clientKey $clientKeyPem | Out-File (Join-Path $outputPath "client-key.pem") -Encoding Ascii # 导出CA密钥为无密码PEM $caKey = Get-Item $caCert.PrivateKey $caKeyPem = ConvertTo-Pem -PrivateKey $caKey $caKeyPem | Out-File (Join-Path $outputPath "ca-key.pem") -Encoding Ascii # 清理临时证书 Remove-Item $caCert.PSPath Remove-Item $clientCert.PSPath
内容的提问来源于stack exchange,提问作者MKANET
相关产品推荐
相关产品推荐

