You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何生成供Azure VM WinRM连接使用的自签名证书并导入Azure Key Vault

实现方案:Azure Key Vault自签名证书生成与导入(适配WinRM连接Azure VM场景)

下面提供两种符合需求的实现方式,均适配WinRM协议对证书的格式要求:

方案1:直接通过Azure.Security.KeyVault.Certificates库生成自签名证书

前置准备

  • 安装依赖NuGet包:Azure.Security.KeyVault.Certificates、Azure.Identity
  • 确保当前操作账号有Key Vault的证书创建权限(Microsoft.KeyVault/vaults/certificates/create权限)

核心实现代码(C#)

using Azure.Identity;
using Azure.Security.KeyVault.Certificates;

// 初始化证书客户端
var vaultUri = new Uri("https://<你的KeyVault名称>.vault.azure.cn/");
var certClient = new CertificateClient(vaultUri, new DefaultAzureCredential());

// 配置适配WinRM的证书策略
var certPolicy = new CertificatePolicy(
    issuerName: "Self",
    subject: "CN=<你的VM域名/主机名>")
{
    KeyType = CertificateKeyType.Rsa,
    KeySize = 2048,
    ReuseKeyOnRenewal = false,
    // 配置密钥用法,满足WinRM要求
    KeyUsage = { CertificateKeyUsage.DigitalSignature, CertificateKeyUsage.KeyEncipherment },
    // 配置增强型密钥用法:必须同时包含服务端和客户端身份验证
    EnhancedKeyUsage = { "1.3.6.1.5.5.7.3.1", "1.3.6.1.5.5.7.3.2" },
    ValidityInMonths = 12,
    Exportable = true
};

// 发起证书创建请求,等待创建完成
var createOp = await certClient.StartCreateCertificateAsync("winrm-vm-cert", certPolicy);
await createOp.WaitForCompletionAsync();

// 创建完成后即可从Key Vault中获取证书
var createdCert = createOp.Value;

注意:如果是国际版Azure,Key Vault域名后缀为.vault.azure.net

方案2:先生成独立自签名证书再导入Azure Key Vault

步骤1:生成本地自签名证书(PowerShell方式)

# 生成符合WinRM要求的自签名证书,DnsName填你的VM公网域名或主机名
$cert = New-SelfSignedCertificate -DnsName "your-vm-public-fqdn" `
    -CertStoreLocation "Cert:\CurrentUser\My" `
    -KeyUsage DigitalSignature,KeyEncipherment `
    -KeyAlgorithm RSA `
    -KeyLength 2048 `
    -NotAfter (Get-Date).AddYears(1) `
    -FriendlyName "WinRM-VM-Cert"

# 导出为PFX格式文件,自行设置导出密码
$pfxPassword = ConvertTo-SecureString "自定义的PFX密码" -AsPlainText -Force
Export-PfxCertificate -Cert "Cert:\CurrentUser\My\$($cert.Thumbprint)" `
    -FilePath "C:\local-path\winrm-cert.pfx" `
    -Password $pfxPassword

步骤2:将PFX证书导入Azure Key Vault(C#代码示例)

using Azure.Identity;
using Azure.Security.KeyVault.Certificates;

var vaultUri = new Uri("https://<你的KeyVault名称>.vault.azure.cn/");
var certClient = new CertificateClient(vaultUri, new DefaultAzureCredential());

// 读取本地PFX文件字节流
var pfxBytes = await File.ReadAllBytesAsync(@"C:\local-path\winrm-cert.pfx");
var importOptions = new ImportCertificateOptions("winrm-vm-imported-cert", pfxBytes)
{
    Password = "你之前设置的PFX导出密码",
    Policy = new CertificatePolicy("Self", "CN=<你的VM域名/主机名>")
    {
        Exportable = true
    }
};

// 执行导入
ImportCertificateResult importedCert = await certClient.ImportCertificateAsync(importOptions);

WinRM连接适配说明

  • 证书生成/导入完成后,需要将证书公钥配置到目标Azure VM的WinRM HTTPS监听器中
  • 本地发起WinRM连接的机器需要将该自签名证书加入受信任根证书颁发机构存储,避免证书校验失败
  • 确保Azure VM的网络安全组开放5986端口(WinRM HTTPS默认端口)的入站访问权限

内容的提问来源于stack exchange,提问作者user3120136

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.26 17:54:03