You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何不使用CloneCert参数,基于现有证书在Cert:\LocalMachine\My创建新证书

Create a Self-Signed Certificate Without Using -CloneCert

If you want to skip the -CloneCert parameter, you can manually pull all critical properties from your existing certificate and pass them directly to New-SelfSignedCertificate. Here's a step-by-step implementation that aligns with your original workflow, replacing the clone logic with explicit property mapping:

Step 1: Import the Existing PFX Certificate (Your Original Workflow)

First, keep your existing import step—this part doesn't need changes:

$securePwd = ConvertTo-SecureString "YourPFXPassword" -AsPlainText -Force
Import-PfxCertificate -Exportable -FilePath encryption.pfx -CertStoreLocation Cert:\LocalMachine\My -Password $securePwd | Out-Null

Step 2: Retrieve the Old Certificate Object

Navigate to the certificate store and fetch your target certificate (replace YOUR_THUMBPRINT with the actual thumbprint of your old cert):

Set-Location -Path "cert:\LocalMachine\My"
$OldCert = Get-ChildItem -Path "YOUR_THUMBPRINT"

Step 3: Extract Key Properties from the Old Certificate

Pull all the attributes we need to replicate in the new certificate:

# Basic subject distinguished name
$subject = $OldCert.Subject

# SAN/DNS names (handles single or multiple names)
$dnsNames = if ($OldCert.DnsNameList) { $OldCert.DnsNameList.Unicode } else { @($subject.Split('=')[-1]) }

# Key usage restrictions (e.g., DigitalSignature, KeyEncipherment)
$keyUsage = $OldCert.KeyUsage

# Enhanced key usage OIDs (e.g., Server Authentication, Client Authentication)
$enhancedKeyUsage = $OldCert.EnhancedKeyUsageList | ForEach-Object { $_.Oid.Value }

# Key algorithm and size (matches the old cert's key specs)
$keyAlgorithm = $OldCert.PublicKey.Oid.FriendlyName
$keyLength = $OldCert.PublicKey.Key.KeySize

# Validity period (use the old cert's end date, or adjust to your needs)
$notBefore = Get-Date
$notAfter = $OldCert.NotAfter # Replace with (Get-Date).AddYears(1) for a custom expiration

Step 4: Generate the New Certificate Without -CloneCert

Use all the extracted properties to create your new certificate:

$newCert = New-SelfSignedCertificate `
    -Subject $subject `
    -DnsName $dnsNames `
    -KeyUsage $keyUsage `
    -EnhancedKeyUsage $enhancedKeyUsage `
    -KeyAlgorithm $keyAlgorithm `
    -KeyLength $keyLength `
    -NotBefore $notBefore `
    -NotAfter $notAfter `
    -CertStoreLocation Cert:\LocalMachine\My `
    -Exportable

Quick Notes

  • SAN Certificates: If your old certificate has multiple DNS names, the $dnsNames variable automatically captures all of them.
  • Custom Validity: Feel free to tweak $notBefore and $notAfter to extend or shorten the new certificate's lifespan.
  • Exportability: The -Exportable parameter ensures you can export the new certificate later, matching your import step's configuration.

内容的提问来源于stack exchange,提问作者user2934433

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 06:32:29