Window上使用openssl+powershell 快速生成文件签名证书
·
- 下载并安装openssl
安装:安装到默认位置,不是默认位置,修改一下脚本的环境路径
- 准备工作目录、脚本、配置
准备一个空白目录,分别放入下面两个文件
openssl.cnf:
在电脑上找一份文件(我的路径是:C:\Program Files\Common Files\SSL\openssl.cnf)复制到工作目录,并修改两处"./demoCA" => "./"
gen.ps1:
# OpenSSL 一键生成签名证书 PowerShell 脚本 # 使用方法: 在 PowerShell 中运行此脚本,确保 openssl 在 PATH 中 # 添加 OpenSSL 路径到 PATH $env:PATH = $env:PATH + ";C:\Program Files\OpenSSL-Win64\bin" # 密码配置(建议从环境变量或安全存储读取) $CA_PASSWORD = "mypassword123" # CA 私钥密码 $PKCS12_PASS = "123456" # PKCS#12 导出密码 # 设置变量 $OPENSSL_CONF = "openssl.cnf" $DAYS_VALID = 365 $KEY_SIZE = 2048 # 颜色输出函数 function Write-ColorOutput($ForegroundColor) { $fc = $host.UI.RawUI.ForegroundColor $host.UI.RawUI.ForegroundColor = $ForegroundColor if ($args) { Write-Host $args } $host.UI.RawUI.ForegroundColor = $fc } Write-ColorOutput Cyan "正在初始化 OpenSSL 证书生成环境..." Write-Host "" # 检查OpenSSL是否可用 try { $opensslVersion = openssl version 2>&1 if ($LASTEXITCODE -ne 0) { throw "OpenSSL 未找到或执行出错: $opensslVersion" } Write-ColorOutput Green "✓ OpenSSL 已就绪: $opensslVersion" } catch { Write-ColorOutput Red "错误: 未找到OpenSSL,请确保已安装OpenSSL并添加到PATH环境变量" Write-Host "错误详情: $_" Read-Host "按 Enter 键退出" exit 1 } if(Test-Path "ca.crt"){ Remove-Item "ca.crt" } # 创建工作目录 $directories = @("certs", "private", "newcerts") foreach ($dir in $directories) { if (Test-Path $dir) { Remove-Item $dir -Recurse -Force } if (-not (Test-Path $dir)) { New-Item -ItemType Directory -Path $dir | Out-Null Write-ColorOutput Yellow "已创建目录: $dir" } } # 初始化索引文件 if (-not (Test-Path "index.txt")) { New-Item -ItemType File -Path "index.txt" | Out-Null } Set-Content -Path "serial" -Value "1000" # 设置证书信息 $COUNTRY = "CN" $STATE = "ChongQing" $LOCALITY = "ChongQing" $ORGANIZATION = "Demo" $ORGUNIT = "SDMS" $COMMONNAME = "demo.ac.cn" $EMAIL = "test@demo.ac.cn" # 生成CA私钥(如果不存在) if (-not (Test-Path "private/ca.key")) { Write-ColorOutput Cyan "正在生成CA私钥..." try { openssl genrsa -out private/ca.key -aes256 -passout pass:$CA_PASSWORD $KEY_SIZE if ($LASTEXITCODE -ne 0) { throw "生成CA私钥失败" } Write-ColorOutput Green "✓ CA私钥生成完成" } catch { Write-ColorOutput Red "错误: $_" Read-Host "按 Enter 键退出" exit 1 } } else { Write-ColorOutput Yellow "CA私钥已存在,跳过生成" } # 生成CA自签名证书(如果不存在) if (-not (Test-Path "ca.crt")) { Write-ColorOutput Cyan "正在生成CA自签名证书..." try { openssl req -new -x509 -days $DAYS_VALID -key private/ca.key -out ca.crt -config $OPENSSL_CONF ` -subj "/C=$COUNTRY/ST=$STATE/L=$LOCALITY/O=$ORGANIZATION/OU=$ORGUNIT/CN=$COMMONNAME/emailAddress=$EMAIL" ` -passin pass:$CA_PASSWORD if ($LASTEXITCODE -ne 0) { throw "生成CA证书失败" } Write-ColorOutput Green "✓ CA证书生成完成" } catch { Write-ColorOutput Red "错误: $_" Read-Host "按 Enter 键退出" exit 1 } } else { Write-ColorOutput Yellow "CA证书已存在,跳过生成" } # 生成服务器私钥 Write-ColorOutput Cyan "正在生成服务器私钥..." try { openssl genrsa -out private/server.key $KEY_SIZE if ($LASTEXITCODE -ne 0) { throw "生成服务器私钥失败" } Write-ColorOutput Green "✓ 服务器私钥生成完成" } catch { Write-ColorOutput Red "错误: $_" Read-Host "按 Enter 键退出" exit 1 } # 生成证书签名请求(CSR) Write-ColorOutput Cyan "正在生成证书签名请求..." try { openssl req -new -key private/server.key -out certs/server.csr -config $OPENSSL_CONF ` -subj "/C=$COUNTRY/ST=$STATE/L=$LOCALITY/O=$ORGANIZATION/OU=$ORGUNIT/CN=$COMMONNAME/emailAddress=$EMAIL" ` -passin pass:$CA_PASSWORD if ($LASTEXITCODE -ne 0) { throw "生成CSR失败" } Write-ColorOutput Green "✓ CSR生成完成" } catch { Write-ColorOutput Red "错误: $_" Read-Host "按 Enter 键退出" exit 1 } # 使用CA签名证书 Write-ColorOutput Cyan "正在使用CA签名证书..." try { openssl ca -batch -config $OPENSSL_CONF -days $DAYS_VALID -in certs/server.csr -out certs/server.crt -keyfile private/ca.key -cert ca.crt -passin pass:$CA_PASSWORD if ($LASTEXITCODE -ne 0) { throw "签名证书失败" } Write-ColorOutput Green "✓ 证书签名完成" } catch { Write-ColorOutput Red "错误: $_" Read-Host "按 Enter 键退出" exit 1 } # 生成PKCS#12格式证书 Write-ColorOutput Cyan "正在生成PKCS#12格式证书..." try { openssl pkcs12 -export -out certs/server_with_password.p12 -inkey private/server.key -in certs/server.crt -certfile ca.crt -passout pass:$PKCS12_PASS if ($LASTEXITCODE -ne 0) { throw "生成PKCS#12证书失败" } Write-ColorOutput Green "✓ PKCS#12证书生成完成" } catch { Write-ColorOutput Red "错误: $_" Read-Host "按 Enter 键退出" exit 1 } # 方法2:从 PEM 格式重新导出 PFX Write-ColorOutput Cyan "正在从 PEM 格式重新导出 PFX..." try { openssl pkcs12 -export -out certs/server_certificate.pfx ` -inkey private/server.key ` -in certs/server.crt ` -certfile ca.crt ` -passout pass:$PKCS12_PASS if ($LASTEXITCODE -ne 0) { throw "从 PEM 格式重新导出 PFX失败" } Write-ColorOutput Green "✓ 从 PEM 格式重新导出 PFX完成" } catch { Write-ColorOutput Red "错误: $_" Read-Host "按 Enter 键退出" exit 1 } # 显示生成结果 Write-Host "" Write-ColorOutput Cyan "==========================================" Write-ColorOutput Cyan "证书生成完成!" Write-ColorOutput Cyan "==========================================" Write-Host "生成的文件:" Write-Host " - CA证书: ca.crt" Write-Host " - CA私钥: private/ca.key" Write-Host " - 服务器证书: certs/server.crt" Write-Host " - 服务器私钥: private/server.key" Write-Host " - 证书签名请求: certs/server.csr" if (Test-Path "certs/server_with_password.p12") { Write-Host " - PKCS#12证书: certs/server_with_password.p12" } Write-Host " - 签名证书: certs/server_certificate.pfx" Write-Host "" Write-ColorOutput Yellow "请妥善保管私钥文件,不要泄露给他人!" Write-Host "" Read-Host "按 Enter 键退出" -
生成证书
每次运行都会重新生成证书
更多推荐



所有评论(0)