You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure KeyVault导入PFX证书后损坏,应用网关无法使用问题排查

问题背景

我从公共CA获取了一份不含中间证书的PEM格式TLS证书,需要将其转换为包含中间证书的PFX格式并存入Azure KeyVault,供应用网关使用。

已执行操作

我通过以下命令成功添加中间证书并转换为PFX格式:

$apiCertSecret | openssl pkcs12 -export -nodes -out /tmp/cert.pfx -CAfile /tmp/certchain.pem -chain `
  -macalg sha256 -certpbe aes-256-cbc -keypbe aes-256-cbc

其中$apiCertSecret是原始证书的文本内容,/tmp/certchain.pem是PEM格式的根证书和中间证书。

生成的PFX证书经**certutil(Windows环境)和openssl(WSL环境)**验证均有效:

  • 执行certutil cert.pfx无错误
  • 执行openssl pkcs12 -info -nokeys -in /tmp/cert.pfx无错误,且显示所有中间证书
问题现象

将该cert.pfx文件通过门户或Import-AzKeyVaultCertificate上传至Azure KeyVault后,证书无法正常使用:

  1. 在应用网关配置中引用该证书时,连接监听器出现unrecognized name错误
  2. 使用openssl s_client -connect测试的完整错误:
error:0A000458:SSL routines:ssl3_read_bytes:tlsv1 unrecognized name:../ssl/record/rec_layer_s3.c:1584:SSL alert number 112
  1. 通过Get-AzKeyVaultSecret -AsPlainText从KeyVault获取该密钥并传入| openssl pkcs12 -info -nokeys,出现以下错误:
140606285837632:error:0D0680A8:asn1 encoding routines:asn1_check_tlen:wrong tag:../crypto/asn1/tasn_dec.c:1149:
140606285837632:error:0D07803A:asn1 encoding routines:asn1_item_embed_d2i:nested asn1 error:../crypto/asn1/tasn_dec.c:309:Type=PKCS12

同一证书直接导入应用网关或Windows证书存储均可正常使用,我希望实现证书升级自动化,优先通过Azure KeyVault让应用网关自动获取更新,但目前KeyVault中的证书存在问题,特提出以下疑问:

  1. 还有哪些命令可用于检查证书以排查问题?
  2. 是否有其他上传证书至Azure KeyVault的方法可避免损坏?
  3. 此问题是否为Azure KeyVault的已知问题?

注:使用的openssl版本为OpenSSL 1.1.1f 31 Mar 2020


解答

1. 额外的证书检查命令

  • 检查PFX文件的ASN.1结构,确认上传前的格式正确性:
    openssl asn1parse -in /tmp/cert.pfx -inform DER
    
  • 验证证书链的完整性和顺序(确保中间证书在用户证书之后,根证书最后):
    openssl verify -CAfile /tmp/certchain.pem /tmp/original-cert.pem
    
  • 提取PFX中的证书链,对比上传前后的内容是否一致:
    # 上传前提取
    openssl pkcs12 -in /tmp/cert.pfx -nokeys -out /tmp/pre-upload-chain.pem
    # 从KeyVault下载后提取(需先将下载的二进制内容保存为文件)
    openssl pkcs12 -in /tmp/post-download.pfx -nokeys -out /tmp/post-upload-chain.pem
    # 对比两个文件的哈希值
    sha256sum /tmp/pre-upload-chain.pem /tmp/post-upload-chain.pem
    
  • 检查PFX文件的密码保护和加密算法兼容性:
    openssl pkcs12 -in /tmp/cert.pfx -info -noout
    

2. 替代的KeyVault证书上传方法

  • 使用Azure CLI上传,避免PowerShell可能的编码问题:
    az keyvault certificate import --vault-name <你的KeyVault名称> --name <证书名称> --file /tmp/cert.pfx --password <PFX密码>
    
  • 调整PFX加密算法:Azure KeyVault对某些高强度加密算法支持有限,尝试生成兼容版PFX:
    $apiCertSecret | openssl pkcs12 -export -nodes -out /tmp/cert-compat.pfx -CAfile /tmp/certchain.pem -chain \
      -macalg sha256 -certpbe aes-128-cbc -keypbe aes-128-cbc
    
  • 拆分上传密钥与证书链:若导入证书功能异常,可将私钥和证书链分别作为Secret上传(注意此方法无法使用证书自动轮换):
    # 上传私钥
    Set-AzKeyVaultSecret -VaultName <你的KeyVault名称> -Name "cert-private-key" -SecretValue (ConvertTo-SecureString (Get-Content /tmp/private-key.pem -Raw) -AsPlainText -Force)
    # 上传证书链
    Set-AzKeyVaultSecret -VaultName <你的KeyVault名称> -Name "cert-chain" -SecretValue (ConvertTo-SecureString (Get-Content /tmp/certchain.pem -Raw) -AsPlainText -Force)
    

3. 已知问题相关说明

Azure KeyVault确实存在过PFX格式兼容性相关的已知问题,常见场景包括:

  • PFX中包含多余的根证书(KeyVault会自动剔除信任存储已有的根证书,处理不当会破坏证书链)
  • OpenSSL 1.1.1f生成的PFX部分ASN.1编码细节与KeyVault的解析逻辑不兼容
  • 使用Import-AzKeyVaultCertificate时,PFX密码含特殊字符会触发隐式编码错误,导致证书损坏

若调整加密算法和上传方式后问题仍存在,可通过Azure支持中心提交工单,确认是否为特定环境下的已知兼容问题。

内容的提问来源于stack exchange,提问作者beavel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 20:15:41