You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell的New-SelfSignedCertificate设置Authority Key Identifier

为自签名证书添加与Subject Key Identifier一致的Authority Key Identifier

你的命令报错是因为New-SelfSignedCertificate在执行阶段还未生成Subject Key Identifier(SKI,OID 2.5.29.14),无法直接通过TextExtension参数引用它来配置Authority Key Identifier(AKI,OID 2.5.29.35)。以下是两种可行的解决方法:

方法一:生成证书后补加AKI

先按原命令生成基础证书,再通过certutil工具修改AKI使其与SKI一致:

  1. 执行原命令生成证书:
New-SelfSignedCertificate -Subject "CN=me.com, OU=ounit, O=company, L=state, C=country" -FriendlyName "me.com" 
 -HashAlgorithm SHA256 -KeyLength 4096 -KeyUsage DigitalSignature,KeyEncipherment 
   -NotAfter (Get-Date).AddDays(1024)  -CertStoreLocation cert:\LocalMachine\My 
    -TextExtension @("2.5.29.19={text}CA=false") -KeyExportPolicy Exportable
  1. 获取证书的Thumbprint(可通过证书管理器或Get-ChildItem cert:\LocalMachine\My查看),导出证书到临时PFX文件:
certutil -exportPFX -p "" -privatekey -machine my <证书Thumbprint> temp.pfx
  1. 提取证书的SKI值:
certutil -dump temp.pfx | findstr /i "Subject Key Identifier"

复制输出中SKI的十六进制值(去掉空格后按字节用空格分隔,比如A1B2C3转为A1 B2 C3)。

  1. 创建名为aki.inf的配置文件,替换<SKI_HEX>为提取的SKI字节:
[Version]
Signature="$Windows NT$"
[Extensions]
2.5.29.35 = "{hex}03 02 00 00 01 01 <SKI_HEX>"
  1. 合并配置生成带AKI的新证书:
certutil -mergePFX -p "" temp.pfx new.pfx @aki.inf
  1. 导入新证书到存储:
Import-PfxCertificate -FilePath new.pfx -CertStoreLocation cert:\LocalMachine\My
  1. 清理临时文件:
Remove-Item temp.pfx, new.pfx, aki.inf

方法二:通过证书请求文件直接生成带AKI的证书

使用certreq工具配合配置文件,可在生成阶段直接设置AKI与SKI一致:

  1. 创建certreq.inf配置文件,替换NotAfter为当前日期加1024天的具体日期(格式MM/dd/yyyy):
[Version]
Signature="$Windows NT$"
[NewRequest]
Subject = "CN=me.com, OU=ounit, O=company, L=state, C=country"
FriendlyName = "me.com"
HashAlgorithm = SHA256
KeyLength = 4096
KeyUsage = 0xA0 ; 对应DigitalSignature、KeyEncipherment
NotAfter = "01/01/2027" ; 替换为(Get-Date).AddDays(1024).ToString("MM/dd/yyyy")的结果
KeyExportPolicy = Exportable
MachineKeySet = TRUE ; 对应CertStoreLocation cert:\LocalMachine\My
[Extensions]
2.5.29.19 = "{text}CA=FALSE"
2.5.29.14 = "" ; 自动生成SKI
2.5.29.35 = "{hex}03 02 00 00 01 01" ; 引用当前证书的SKI作为AKI
  1. 生成证书请求:
certreq -new certreq.inf certreq.req
  1. 签发自签名证书:
certreq -sign certreq.req cert.cer
  1. 导入证书到本地机器存储:
certutil -addstore -machine my cert.cer
  1. (可选)导出带私钥的PFX文件:
$thumbprint = (Get-ChildItem cert:\LocalMachine\My | Where-Object {$_.Subject -match "CN=me.com"}).Thumbprint
certutil -exportPFX -p "" -privatekey -machine my $thumbprint cert.pfx
  1. 清理临时文件:
Remove-Item certreq.inf, certreq.req, cert.cer

验证结果

打开Windows证书管理器,找到目标证书,查看「详细信息」标签,确认「Authority Key Identifier」和「Subject Key Identifier」的值完全一致。

内容的提问来源于stack exchange,提问作者tks.tman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 06:25:22