You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从Azure VM导出.pfx文件至Azure门户配置安全LDAP

Exporting .pfx Certificate from Azure VM for Azure AD DS Secure LDAP

Got it, let's break down how to export that .pfx file from your Azure VM so you can upload it to the portal for configuring secure LDAP in Azure AD Domain Services. I'll cover both Windows and Linux VMs since you didn't specify your OS.

For Windows VMs

Graphical Method (Using Certificate Manager)

  • Open the Local Computer Certificate Store by pressing Win + R, typing certlm.msc, and hitting Enter.
  • Navigate to Personal > Certificates and locate the certificate you created earlier.
  • Right-click the certificate > All Tasks > Export to launch the Certificate Export Wizard.
    • Select Yes, export the private key (this is critical—Azure AD DS needs the private key in the .pfx).
    • Choose Personal Information Exchange - PKCS #12 (.PFX) as the format. Make sure to check the boxes for "Include all certificates in the certification path if possible" and "Enable certificate privacy" (if available).
    • Set a strong password for the .pfx file (you’ll need this when uploading to the Azure portal—don’t forget it!).
    • Pick a save location (like your VM’s desktop) and name the file.
  • Transfer the .pfx to your local machine: You can drag-and-drop it over your RDP session, or use Azure Storage Explorer to upload it to a storage account then download it locally.

PowerShell Method (Faster for Automation)

If you prefer command-line, run this in an elevated PowerShell window:

# Replace "your-certificate-subject" with the subject name of your certificate
$cert = Get-ChildItem -Path Cert:\LocalMachine\My | Where-Object {$_.Subject -match "your-certificate-subject"}

# Replace the file path and password with your own
Export-PfxCertificate -Cert $cert -FilePath "C:\temp\aad-ds-ldaps.pfx" -Password (ConvertTo-SecureString "YourStrongPassword123!" -AsPlainText -Force)

Then transfer the file from C:\temp to your local machine using the same methods above.

For Linux VMs

Assuming you used OpenSSL to generate your certificate and private key, follow these steps to combine them into a .pfx:

  1. Open a terminal on your Linux VM and navigate to the directory where your certificate (e.g., cert.pem) and private key (e.g., private.key) are stored.
  2. Run this OpenSSL command to create the .pfx file:
openssl pkcs12 -export -out aad-ds-ldaps.pfx -inkey private.key -in cert.pem

You’ll be prompted to set an export password—make it strong and note it down for later.
3. Download the .pfx to your local machine: Use SCP from your local terminal (replace placeholders with your VM details):

scp your-linux-username@vm-public-ip:/path/to/aad-ds-ldaps.pfx /local/directory/on/your/computer

Alternatively, you can use the Azure Portal’s Run Command feature or Azure CLI to copy the file to a storage account for download.

Key Notes

  • Ensure your .pfx includes the private key—without it, Azure AD DS won’t accept the certificate for secure LDAP.
  • The password you set during export must meet Azure’s complexity requirements (minimum 8 characters, mix of uppercase, lowercase, numbers, and special characters).
  • Double-check that your VM’s network security group allows the necessary file transfer ports (3389 for RDP, 22 for SSH/SCP) if you’re transferring directly to your local machine.

内容的提问来源于stack exchange,提问作者user9314128

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:20:55