如何通过PowerShell的New-SelfSignedCertificate设置Authority Key Identifier
你的命令报错是因为New-SelfSignedCertificate在执行阶段还未生成Subject Key Identifier(SKI,OID 2.5.29.14),无法直接通过TextExtension参数引用它来配置Authority Key Identifier(AKI,OID 2.5.29.35)。以下是两种可行的解决方法:
方法一:生成证书后补加AKI
先按原命令生成基础证书,再通过certutil工具修改AKI使其与SKI一致:
- 执行原命令生成证书:
New-SelfSignedCertificate -Subject "CN=me.com, OU=ounit, O=company, L=state, C=country" -FriendlyName "me.com" -HashAlgorithm SHA256 -KeyLength 4096 -KeyUsage DigitalSignature,KeyEncipherment -NotAfter (Get-Date).AddDays(1024) -CertStoreLocation cert:\LocalMachine\My -TextExtension @("2.5.29.19={text}CA=false") -KeyExportPolicy Exportable
- 获取证书的Thumbprint(可通过证书管理器或
Get-ChildItem cert:\LocalMachine\My查看),导出证书到临时PFX文件:
certutil -exportPFX -p "" -privatekey -machine my <证书Thumbprint> temp.pfx
- 提取证书的SKI值:
certutil -dump temp.pfx | findstr /i "Subject Key Identifier"
复制输出中SKI的十六进制值(去掉空格后按字节用空格分隔,比如A1B2C3转为A1 B2 C3)。
- 创建名为
aki.inf的配置文件,替换<SKI_HEX>为提取的SKI字节:
[Version] Signature="$Windows NT$" [Extensions] 2.5.29.35 = "{hex}03 02 00 00 01 01 <SKI_HEX>"
- 合并配置生成带AKI的新证书:
certutil -mergePFX -p "" temp.pfx new.pfx @aki.inf
- 导入新证书到存储:
Import-PfxCertificate -FilePath new.pfx -CertStoreLocation cert:\LocalMachine\My
- 清理临时文件:
Remove-Item temp.pfx, new.pfx, aki.inf
方法二:通过证书请求文件直接生成带AKI的证书
使用certreq工具配合配置文件,可在生成阶段直接设置AKI与SKI一致:
- 创建
certreq.inf配置文件,替换NotAfter为当前日期加1024天的具体日期(格式MM/dd/yyyy):
[Version] Signature="$Windows NT$" [NewRequest] Subject = "CN=me.com, OU=ounit, O=company, L=state, C=country" FriendlyName = "me.com" HashAlgorithm = SHA256 KeyLength = 4096 KeyUsage = 0xA0 ; 对应DigitalSignature、KeyEncipherment NotAfter = "01/01/2027" ; 替换为(Get-Date).AddDays(1024).ToString("MM/dd/yyyy")的结果 KeyExportPolicy = Exportable MachineKeySet = TRUE ; 对应CertStoreLocation cert:\LocalMachine\My [Extensions] 2.5.29.19 = "{text}CA=FALSE" 2.5.29.14 = "" ; 自动生成SKI 2.5.29.35 = "{hex}03 02 00 00 01 01" ; 引用当前证书的SKI作为AKI
- 生成证书请求:
certreq -new certreq.inf certreq.req
- 签发自签名证书:
certreq -sign certreq.req cert.cer
- 导入证书到本地机器存储:
certutil -addstore -machine my cert.cer
- (可选)导出带私钥的PFX文件:
$thumbprint = (Get-ChildItem cert:\LocalMachine\My | Where-Object {$_.Subject -match "CN=me.com"}).Thumbprint certutil -exportPFX -p "" -privatekey -machine my $thumbprint cert.pfx
- 清理临时文件:
Remove-Item certreq.inf, certreq.req, cert.cer
验证结果
打开Windows证书管理器,找到目标证书,查看「详细信息」标签,确认「Authority Key Identifier」和「Subject Key Identifier」的值完全一致。
内容的提问来源于stack exchange,提问作者tks.tman
相关产品推荐
相关产品推荐

