如何不使用CloneCert参数,基于现有证书在Cert:\LocalMachine\My创建新证书
Create a Self-Signed Certificate Without Using
-CloneCert If you want to skip the -CloneCert parameter, you can manually pull all critical properties from your existing certificate and pass them directly to New-SelfSignedCertificate. Here's a step-by-step implementation that aligns with your original workflow, replacing the clone logic with explicit property mapping:
Step 1: Import the Existing PFX Certificate (Your Original Workflow)
First, keep your existing import step—this part doesn't need changes:
$securePwd = ConvertTo-SecureString "YourPFXPassword" -AsPlainText -Force Import-PfxCertificate -Exportable -FilePath encryption.pfx -CertStoreLocation Cert:\LocalMachine\My -Password $securePwd | Out-Null
Step 2: Retrieve the Old Certificate Object
Navigate to the certificate store and fetch your target certificate (replace YOUR_THUMBPRINT with the actual thumbprint of your old cert):
Set-Location -Path "cert:\LocalMachine\My" $OldCert = Get-ChildItem -Path "YOUR_THUMBPRINT"
Step 3: Extract Key Properties from the Old Certificate
Pull all the attributes we need to replicate in the new certificate:
# Basic subject distinguished name $subject = $OldCert.Subject # SAN/DNS names (handles single or multiple names) $dnsNames = if ($OldCert.DnsNameList) { $OldCert.DnsNameList.Unicode } else { @($subject.Split('=')[-1]) } # Key usage restrictions (e.g., DigitalSignature, KeyEncipherment) $keyUsage = $OldCert.KeyUsage # Enhanced key usage OIDs (e.g., Server Authentication, Client Authentication) $enhancedKeyUsage = $OldCert.EnhancedKeyUsageList | ForEach-Object { $_.Oid.Value } # Key algorithm and size (matches the old cert's key specs) $keyAlgorithm = $OldCert.PublicKey.Oid.FriendlyName $keyLength = $OldCert.PublicKey.Key.KeySize # Validity period (use the old cert's end date, or adjust to your needs) $notBefore = Get-Date $notAfter = $OldCert.NotAfter # Replace with (Get-Date).AddYears(1) for a custom expiration
Step 4: Generate the New Certificate Without -CloneCert
Use all the extracted properties to create your new certificate:
$newCert = New-SelfSignedCertificate ` -Subject $subject ` -DnsName $dnsNames ` -KeyUsage $keyUsage ` -EnhancedKeyUsage $enhancedKeyUsage ` -KeyAlgorithm $keyAlgorithm ` -KeyLength $keyLength ` -NotBefore $notBefore ` -NotAfter $notAfter ` -CertStoreLocation Cert:\LocalMachine\My ` -Exportable
Quick Notes
- SAN Certificates: If your old certificate has multiple DNS names, the
$dnsNamesvariable automatically captures all of them. - Custom Validity: Feel free to tweak
$notBeforeand$notAfterto extend or shorten the new certificate's lifespan. - Exportability: The
-Exportableparameter ensures you can export the new certificate later, matching your import step's configuration.
内容的提问来源于stack exchange,提问作者user2934433
相关产品推荐
相关产品推荐

