如何使用easy-rsa生成的证书签署PowerShell脚本
Alright, let's break down exactly how to reuse your existing Linux CA setup with Easy-RSA to get certificates signed by a Windows Server 2012 R2 CA, then prep everything for your deployment scripts. Here's a step-by-step guide tailored to your workflow:
Step 1: Generate a Certificate Signing Request (CSR) with Easy-RSA on your Linux server
- First off, navigate to your Easy-RSA directory (usually something like
/etc/openvpn/easy-rsa/or wherever you’ve set it up) and load your CA configuration by sourcing the vars file:cd /path/to/easy-rsa source vars - Clean up any old request files to avoid conflicts:
./clean-all - Generate the CSR and private key (replace
client1with your preferred certificate name):./build-key --nopass client1When prompted, fill in the details to match your existing CA’s requirements. Make sure the Common Name (CN) is unique for each certificate you generate.
- Once finished, you’ll find the CSR file at
./keys/client1.csr— this is the file you’ll need to transfer to the Windows Server 2012 R2 CA.
Step 2: Sign the CSR on Windows Server 2012 R2 CA
- Transfer the
.csrfile to the Windows server using a secure method like SCP, SFTP, or encrypted file transfer. - Open the Certificate Authority console on Server 2012 R2.
- Right-click your CA name > All Tasks > Submit new request.
- Browse to the transferred
.csrfile and open it. - In the pending requests list, locate your new request, right-click it > All Tasks > Issue.
- Navigate to the Issued Certificates folder, find the newly issued certificate, right-click > All Tasks > Export.
- Choose either DER encoded binary X.509 (.CER) or Base-64 encoded X.509 (.CER) (pick the format your deployment script expects — most Linux-based scripts prefer PEM, which is the base64 variant). Save the exported file (e.g.,
client1.cer).
Step 3: Import the Signed Certificate and Required Files back to your Deployment Script Server
- Transfer the signed
.cerfile back to your Linux deployment server. - Ensure you have these critical files from your existing Linux CA setup ready for the deployment script:
- The CA root certificate (
ca.crt— usually in your Easy-RSAkeys/directory) - The private key for the certificate you generated (
client1.key— also in thekeys/directory)
- The CA root certificate (
- If you exported the signed cert in DER format, convert it to PEM if needed (common for Linux workflows):
openssl x509 -inform der -in client1.cer -out client1.crt - Verify the certificate chain to confirm everything is valid:
You should seeopenssl verify -CAfile ca.crt client1.crtclient1.crt: OKif the chain checks out.
Quick Tips to Avoid Headaches
- Make sure the subject details (Country, State, Organization, etc.) on the CSR match what your Windows CA enforces — some CAs require these values to align with the CA’s own settings.
- For OpenVPN deployments, remember clients will need the
ca.crt, their uniqueclient1.crt, andclient1.keyfiles to connect. - Never transfer private keys over unencrypted channels — keep them secure at all times.
内容的提问来源于stack exchange,提问作者dghodgson
相关产品推荐
相关产品推荐

