You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用easy-rsa生成的证书签署PowerShell脚本

Alright, let's break down exactly how to reuse your existing Linux CA setup with Easy-RSA to get certificates signed by a Windows Server 2012 R2 CA, then prep everything for your deployment scripts. Here's a step-by-step guide tailored to your workflow:

Step 1: Generate a Certificate Signing Request (CSR) with Easy-RSA on your Linux server
  • First off, navigate to your Easy-RSA directory (usually something like /etc/openvpn/easy-rsa/ or wherever you’ve set it up) and load your CA configuration by sourcing the vars file:
    cd /path/to/easy-rsa
    source vars
    
  • Clean up any old request files to avoid conflicts:
    ./clean-all
    
  • Generate the CSR and private key (replace client1 with your preferred certificate name):
    ./build-key --nopass client1
    

    When prompted, fill in the details to match your existing CA’s requirements. Make sure the Common Name (CN) is unique for each certificate you generate.

  • Once finished, you’ll find the CSR file at ./keys/client1.csr — this is the file you’ll need to transfer to the Windows Server 2012 R2 CA.
Step 2: Sign the CSR on Windows Server 2012 R2 CA
  • Transfer the .csr file to the Windows server using a secure method like SCP, SFTP, or encrypted file transfer.
  • Open the Certificate Authority console on Server 2012 R2.
  • Right-click your CA name > All Tasks > Submit new request.
  • Browse to the transferred .csr file and open it.
  • In the pending requests list, locate your new request, right-click it > All Tasks > Issue.
  • Navigate to the Issued Certificates folder, find the newly issued certificate, right-click > All Tasks > Export.
  • Choose either DER encoded binary X.509 (.CER) or Base-64 encoded X.509 (.CER) (pick the format your deployment script expects — most Linux-based scripts prefer PEM, which is the base64 variant). Save the exported file (e.g., client1.cer).
Step 3: Import the Signed Certificate and Required Files back to your Deployment Script Server
  • Transfer the signed .cer file back to your Linux deployment server.
  • Ensure you have these critical files from your existing Linux CA setup ready for the deployment script:
    • The CA root certificate (ca.crt — usually in your Easy-RSA keys/ directory)
    • The private key for the certificate you generated (client1.key — also in the keys/ directory)
  • If you exported the signed cert in DER format, convert it to PEM if needed (common for Linux workflows):
    openssl x509 -inform der -in client1.cer -out client1.crt
    
  • Verify the certificate chain to confirm everything is valid:
    openssl verify -CAfile ca.crt client1.crt
    
    You should see client1.crt: OK if the chain checks out.
Quick Tips to Avoid Headaches
  • Make sure the subject details (Country, State, Organization, etc.) on the CSR match what your Windows CA enforces — some CAs require these values to align with the CA’s own settings.
  • For OpenVPN deployments, remember clients will need the ca.crt, their unique client1.crt, and client1.key files to connect.
  • Never transfer private keys over unencrypted channels — keep them secure at all times.

内容的提问来源于stack exchange,提问作者dghodgson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:00:39