You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在ASP.Net Core 2.0的Kestrel中直接使用PEM证书实现HTTPS?

直接在ASP.NET Core 2.0 Kestrel中使用Let's Encrypt PEM证书(无需外部转换)

当然可行!ASP.NET Core 2.0的Kestrel服务器完全支持直接加载Let's Encrypt生成的PEM格式证书和私钥,不需要提前转换成PFX格式。下面我会分两种常用方式给你说明具体实现:

方式一:通过代码配置(最可靠,兼容性强)

你可以在Program.cs中直接编写代码加载PEM证书和私钥,这种方式在ASP.NET Core 2.0中完全生效:

using System.IO;
using System.Security.Cryptography;
using System.Security.Cryptography.X509Certificates;
using Microsoft.AspNetCore;
using Microsoft.AspNetCore.Hosting;
using Microsoft.AspNetCore.Server.Kestrel.Core;

namespace YourAppNamespace
{
    public class Program
    {
        public static IWebHost BuildWebHost(string[] args) =>
            WebHost.CreateDefaultBuilder(args)
                .UseStartup<Startup>()
                .UseKestrel(options =>
                {
                    // 配置HTTPS监听端口(443)
                    options.ListenAnyIP(443, listenOptions =>
                    {
                        // 加载证书链(fullchain.pem包含主证书和中间证书)
                        var certPath = Path.Combine(Directory.GetCurrentDirectory(), "Certificates", "fullchain.pem");
                        var certBytes = File.ReadAllBytes(certPath);
                        var certificate = new X509Certificate2(certBytes);

                        // 加载私钥文件(privkey.pem)
                        var privateKeyPath = Path.Combine(Directory.GetCurrentDirectory(), "Certificates", "privkey.pem");
                        var privateKeyText = File.ReadAllText(privateKeyPath);
                        using var rsa = RSA.Create();
                        rsa.ImportFromPem(privateKeyText);

                        // 将私钥与证书关联
                        certificate = certificate.CopyWithPrivateKey(rsa);

                        // 启用HTTPS
                        listenOptions.UseHttps(certificate);
                    });
                })
                .Build();

        public static void Main(string[] args)
        {
            BuildWebHost(args).Run();
        }
    }
}

代码说明:

  • fullchain.pem:Let's Encrypt生成的完整证书链文件,包含你的域名证书和信任的中间证书
  • privkey.pem:对应域名的私钥文件
  • 记得把证书文件放在项目目录下(比如新建Certificates文件夹),并确保在发布时包含这些文件(可以在.csproj中添加<Content Include="Certificates/**/*" />)

方式二:通过配置文件(简化配置)

ASP.NET Core 2.0的Kestrel也支持通过appsettings.json直接配置PEM证书,不过需要确保配置项正确:

{
  "Kestrel": {
    "EndPoints": {
      "Https": {
        "Url": "https://*:443",
        "Certificate": {
          "Path": "Certificates/fullchain.pem",
          "KeyPath": "Certificates/privkey.pem",
          "Password": ""
        }
      }
    }
  }
}

注意事项:

  • 配置文件方式依赖Kestrel的内置证书加载逻辑,在ASP.NET Core 2.0中是支持的,但如果遇到加载问题,优先用代码方式
  • 私钥文件的权限要严格控制:在Linux系统上建议设置为chmod 600 privkey.pem,避免其他用户读取;Windows系统也要限制文件的访问权限

额外提醒:证书续期

Let's Encrypt证书有效期只有90天,所以你需要实现自动续期逻辑:

  1. 使用certbot等工具自动续期PEM证书
  2. 证书更新后,ASP.NET Core 2.0默认不会自动重载证书,你可以:
    • 编写文件监听逻辑,当证书文件变化时重启Kestrel的HTTPS端点
    • 或者在续期完成后重启应用程序

内容的提问来源于stack exchange,提问作者Mohammed Noureldin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:01:37