You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用PowerShell筛选CA服务器已颁发证书并导出为CSV文件

从CA筛选已颁发证书并导出CSV的实现方案
  • 你当前的certutil命令未添加状态筛选规则,要仅返回已颁发证书,追加-restrict "Disposition=20"参数即可:证书状态枚举中20对应已颁发状态,其他常见状态枚举值如下:
    • 20:已颁发
    • 30:证书申请被拒绝
    • 31:证书已吊销
    • 19:证书申请待审核
  • 带筛选的基础查询命令:
certutil -view -restrict "Disposition=20" -out "RequestID,RequesterName,RequestType,NotAfter,CommonName,CertificateTemplate,SerialNumber"
  • 原生certutil返回的是格式化纯文本,无法直接导出为结构化CSV,可直接使用下方封装好的PowerShell脚本,执行后自动解析结果并导出CSV:
# 自定义CSV导出保存路径
$csvSavePath = "C:\Issued_CA_Certs.csv"

# 执行带状态筛选的证书查询
$queryResult = certutil -view -restrict "Disposition=20" -out "RequestID,RequesterName,RequestType,NotAfter,CommonName,CertificateTemplate,SerialNumber"

# 解析输出为结构化对象
$certList = @()
$tempCert = [ordered]@{}
foreach ($line in $queryResult) {
    if ($line -match '^Row \d+:') {
        if ($tempCert.Count -ne 0) {
            $certList += [PSCustomObject]$tempCert
            $tempCert = [ordered]@{}
        }
        continue
    }
    if ($line -match '^\s{2}(\w+):\s+(.*)$') {
        $prop = $matches[1]
        $value = $matches[2].Trim()
        # 清理证书模板字段多余的OID标识内容
        if ($prop -eq 'CertificateTemplate') {
            $value = $value.Split('\n')[0].Trim()
        }
        $tempCert[$prop] = $value
    }
}
# 追加最后一条证书记录
if ($tempCert.Count -ne 0) {
    $certList += [PSCustomObject]$tempCert
}

# 导出CSV文件
$certList | Export-Csv -Path $csvSavePath -NoTypeInformation -Encoding UTF8
Write-Host "导出完成,共获取 $($certList.Count) 条已颁发证书记录,文件保存至:$csvSavePath"

执行提示:运行上述命令/脚本需要使用具备CA查询权限的账号;如果需要远程查询指定CA服务器,在certutil命令中追加-config "CA服务器主机名\CA实例名称"参数即可。

内容的提问来源于stack exchange,提问作者krishna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.28 12:36:20