Azure KeyVault导入PFX证书后损坏,应用网关无法使用问题排查
问题背景
我从公共CA获取了一份不含中间证书的PEM格式TLS证书,需要将其转换为包含中间证书的PFX格式并存入Azure KeyVault,供应用网关使用。
已执行操作
我通过以下命令成功添加中间证书并转换为PFX格式:
$apiCertSecret | openssl pkcs12 -export -nodes -out /tmp/cert.pfx -CAfile /tmp/certchain.pem -chain ` -macalg sha256 -certpbe aes-256-cbc -keypbe aes-256-cbc
其中$apiCertSecret是原始证书的文本内容,/tmp/certchain.pem是PEM格式的根证书和中间证书。
生成的PFX证书经**certutil(Windows环境)和openssl(WSL环境)**验证均有效:
- 执行
certutil cert.pfx无错误 - 执行
openssl pkcs12 -info -nokeys -in /tmp/cert.pfx无错误,且显示所有中间证书
问题现象
将该cert.pfx文件通过门户或Import-AzKeyVaultCertificate上传至Azure KeyVault后,证书无法正常使用:
- 在应用网关配置中引用该证书时,连接监听器出现
unrecognized name错误 - 使用
openssl s_client -connect测试的完整错误:
error:0A000458:SSL routines:ssl3_read_bytes:tlsv1 unrecognized name:../ssl/record/rec_layer_s3.c:1584:SSL alert number 112
- 通过
Get-AzKeyVaultSecret -AsPlainText从KeyVault获取该密钥并传入| openssl pkcs12 -info -nokeys,出现以下错误:
140606285837632:error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag:../crypto/asn1/tasn_dec.c:1149: 140606285837632:error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error:../crypto/asn1/tasn_dec.c:309:Type=PKCS12
同一证书直接导入应用网关或Windows证书存储均可正常使用,我希望实现证书升级自动化,优先通过Azure KeyVault让应用网关自动获取更新,但目前KeyVault中的证书存在问题,特提出以下疑问:
- 还有哪些命令可用于检查证书以排查问题?
- 是否有其他上传证书至Azure KeyVault的方法可避免损坏?
- 此问题是否为Azure KeyVault的已知问题?
注:使用的openssl版本为OpenSSL 1.1.1f 31 Mar 2020
解答
1. 额外的证书检查命令
- 检查PFX文件的ASN.1结构,确认上传前的格式正确性:
openssl asn1parse -in /tmp/cert.pfx -inform DER - 验证证书链的完整性和顺序(确保中间证书在用户证书之后,根证书最后):
openssl verify -CAfile /tmp/certchain.pem /tmp/original-cert.pem - 提取PFX中的证书链,对比上传前后的内容是否一致:
# 上传前提取 openssl pkcs12 -in /tmp/cert.pfx -nokeys -out /tmp/pre-upload-chain.pem # 从KeyVault下载后提取(需先将下载的二进制内容保存为文件) openssl pkcs12 -in /tmp/post-download.pfx -nokeys -out /tmp/post-upload-chain.pem # 对比两个文件的哈希值 sha256sum /tmp/pre-upload-chain.pem /tmp/post-upload-chain.pem - 检查PFX文件的密码保护和加密算法兼容性:
openssl pkcs12 -in /tmp/cert.pfx -info -noout
2. 替代的KeyVault证书上传方法
- 使用Azure CLI上传,避免PowerShell可能的编码问题:
az keyvault certificate import --vault-name <你的KeyVault名称> --name <证书名称> --file /tmp/cert.pfx --password <PFX密码> - 调整PFX加密算法:Azure KeyVault对某些高强度加密算法支持有限,尝试生成兼容版PFX:
$apiCertSecret | openssl pkcs12 -export -nodes -out /tmp/cert-compat.pfx -CAfile /tmp/certchain.pem -chain \ -macalg sha256 -certpbe aes-128-cbc -keypbe aes-128-cbc - 拆分上传密钥与证书链:若导入证书功能异常,可将私钥和证书链分别作为Secret上传(注意此方法无法使用证书自动轮换):
# 上传私钥 Set-AzKeyVaultSecret -VaultName <你的KeyVault名称> -Name "cert-private-key" -SecretValue (ConvertTo-SecureString (Get-Content /tmp/private-key.pem -Raw) -AsPlainText -Force) # 上传证书链 Set-AzKeyVaultSecret -VaultName <你的KeyVault名称> -Name "cert-chain" -SecretValue (ConvertTo-SecureString (Get-Content /tmp/certchain.pem -Raw) -AsPlainText -Force)
3. 已知问题相关说明
Azure KeyVault确实存在过PFX格式兼容性相关的已知问题,常见场景包括:
- PFX中包含多余的根证书(KeyVault会自动剔除信任存储已有的根证书,处理不当会破坏证书链)
- OpenSSL 1.1.1f生成的PFX部分ASN.1编码细节与KeyVault的解析逻辑不兼容
- 使用
Import-AzKeyVaultCertificate时,PFX密码含特殊字符会触发隐式编码错误,导致证书损坏
若调整加密算法和上传方式后问题仍存在,可通过Azure支持中心提交工单,确认是否为特定环境下的已知兼容问题。
内容的提问来源于stack exchange,提问作者beavel
相关产品推荐
相关产品推荐

