如何生成供Azure VM WinRM连接使用的自签名证书并导入Azure Key Vault
实现方案:Azure Key Vault自签名证书生成与导入(适配WinRM连接Azure VM场景)
下面提供两种符合需求的实现方式,均适配WinRM协议对证书的格式要求:
方案1:直接通过Azure.Security.KeyVault.Certificates库生成自签名证书
前置准备
- 安装依赖NuGet包:
Azure.Security.KeyVault.Certificates、Azure.Identity - 确保当前操作账号有Key Vault的证书创建权限(
Microsoft.KeyVault/vaults/certificates/create权限)
核心实现代码(C#)
using Azure.Identity; using Azure.Security.KeyVault.Certificates; // 初始化证书客户端 var vaultUri = new Uri("https://<你的KeyVault名称>.vault.azure.cn/"); var certClient = new CertificateClient(vaultUri, new DefaultAzureCredential()); // 配置适配WinRM的证书策略 var certPolicy = new CertificatePolicy( issuerName: "Self", subject: "CN=<你的VM域名/主机名>") { KeyType = CertificateKeyType.Rsa, KeySize = 2048, ReuseKeyOnRenewal = false, // 配置密钥用法,满足WinRM要求 KeyUsage = { CertificateKeyUsage.DigitalSignature, CertificateKeyUsage.KeyEncipherment }, // 配置增强型密钥用法:必须同时包含服务端和客户端身份验证 EnhancedKeyUsage = { "1.3.6.1.5.5.7.3.1", "1.3.6.1.5.5.7.3.2" }, ValidityInMonths = 12, Exportable = true }; // 发起证书创建请求,等待创建完成 var createOp = await certClient.StartCreateCertificateAsync("winrm-vm-cert", certPolicy); await createOp.WaitForCompletionAsync(); // 创建完成后即可从Key Vault中获取证书 var createdCert = createOp.Value;
注意:如果是国际版Azure,Key Vault域名后缀为.vault.azure.net
方案2:先生成独立自签名证书再导入Azure Key Vault
步骤1:生成本地自签名证书(PowerShell方式)
# 生成符合WinRM要求的自签名证书,DnsName填你的VM公网域名或主机名 $cert = New-SelfSignedCertificate -DnsName "your-vm-public-fqdn" ` -CertStoreLocation "Cert:\CurrentUser\My" ` -KeyUsage DigitalSignature,KeyEncipherment ` -KeyAlgorithm RSA ` -KeyLength 2048 ` -NotAfter (Get-Date).AddYears(1) ` -FriendlyName "WinRM-VM-Cert" # 导出为PFX格式文件,自行设置导出密码 $pfxPassword = ConvertTo-SecureString "自定义的PFX密码" -AsPlainText -Force Export-PfxCertificate -Cert "Cert:\CurrentUser\My\$($cert.Thumbprint)" ` -FilePath "C:\local-path\winrm-cert.pfx" ` -Password $pfxPassword
步骤2:将PFX证书导入Azure Key Vault(C#代码示例)
using Azure.Identity; using Azure.Security.KeyVault.Certificates; var vaultUri = new Uri("https://<你的KeyVault名称>.vault.azure.cn/"); var certClient = new CertificateClient(vaultUri, new DefaultAzureCredential()); // 读取本地PFX文件字节流 var pfxBytes = await File.ReadAllBytesAsync(@"C:\local-path\winrm-cert.pfx"); var importOptions = new ImportCertificateOptions("winrm-vm-imported-cert", pfxBytes) { Password = "你之前设置的PFX导出密码", Policy = new CertificatePolicy("Self", "CN=<你的VM域名/主机名>") { Exportable = true } }; // 执行导入 ImportCertificateResult importedCert = await certClient.ImportCertificateAsync(importOptions);
WinRM连接适配说明
- 证书生成/导入完成后,需要将证书公钥配置到目标Azure VM的WinRM HTTPS监听器中
- 本地发起WinRM连接的机器需要将该自签名证书加入受信任根证书颁发机构存储,避免证书校验失败
- 确保Azure VM的网络安全组开放5986端口(WinRM HTTPS默认端口)的入站访问权限
内容的提问来源于stack exchange,提问作者user3120136
相关产品推荐
相关产品推荐

