1. 下载并安装openssl

    下载:openssl Windows版下载地址

    安装:安装到默认位置,不是默认位置,修改一下脚本的环境路径

  2. 准备工作目录、脚本、配置

    准备一个空白目录,分别放入下面两个文件

    openssl.cnf:

    在电脑上找一份文件(我的路径是:C:\Program Files\Common Files\SSL\openssl.cnf)复制到工作目录,并修改两处"./demoCA" => "./"

    gen.ps1:

    # OpenSSL 一键生成签名证书 PowerShell 脚本
    # 使用方法: 在 PowerShell 中运行此脚本,确保 openssl 在 PATH 中
    
    # 添加 OpenSSL 路径到 PATH
    $env:PATH = $env:PATH + ";C:\Program Files\OpenSSL-Win64\bin"
    
    # 密码配置(建议从环境变量或安全存储读取)
    $CA_PASSWORD = "mypassword123"  # CA 私钥密码
    $PKCS12_PASS = "123456"         # PKCS#12 导出密码
    
    # 设置变量
    $OPENSSL_CONF = "openssl.cnf"
    $DAYS_VALID = 365
    $KEY_SIZE = 2048
    
    # 颜色输出函数
    function Write-ColorOutput($ForegroundColor) {
        $fc = $host.UI.RawUI.ForegroundColor
        $host.UI.RawUI.ForegroundColor = $ForegroundColor
        if ($args) {
            Write-Host $args
        }
        $host.UI.RawUI.ForegroundColor = $fc
    }
    
    Write-ColorOutput Cyan "正在初始化 OpenSSL 证书生成环境..."
    Write-Host ""
    
    # 检查OpenSSL是否可用
    try {
        $opensslVersion = openssl version 2>&1
        if ($LASTEXITCODE -ne 0) {
            throw "OpenSSL 未找到或执行出错: $opensslVersion"
        }
        Write-ColorOutput Green "✓ OpenSSL 已就绪: $opensslVersion"
    } catch {
        Write-ColorOutput Red "错误: 未找到OpenSSL,请确保已安装OpenSSL并添加到PATH环境变量"
        Write-Host "错误详情: $_"
        Read-Host "按 Enter 键退出"
        exit 1
    }
    
    if(Test-Path "ca.crt"){
        Remove-Item "ca.crt"
    }
    
    # 创建工作目录
    $directories = @("certs", "private", "newcerts")
    foreach ($dir in $directories) {
        if (Test-Path $dir) {
            Remove-Item $dir -Recurse -Force
        }
        if (-not (Test-Path $dir)) {
            New-Item -ItemType Directory -Path $dir | Out-Null
            Write-ColorOutput Yellow "已创建目录: $dir"
        }
    }
    
    # 初始化索引文件
    if (-not (Test-Path "index.txt")) {
        New-Item -ItemType File -Path "index.txt" | Out-Null
    }
    Set-Content -Path "serial" -Value "1000"
    
    # 设置证书信息
    $COUNTRY = "CN"
    $STATE = "ChongQing"
    $LOCALITY = "ChongQing"
    $ORGANIZATION = "Demo"
    $ORGUNIT = "SDMS"
    $COMMONNAME = "demo.ac.cn"
    $EMAIL = "test@demo.ac.cn"
    
    # 生成CA私钥(如果不存在)
    if (-not (Test-Path "private/ca.key")) {
        Write-ColorOutput Cyan "正在生成CA私钥..."
        try {
            openssl genrsa -out private/ca.key -aes256 -passout pass:$CA_PASSWORD $KEY_SIZE
            if ($LASTEXITCODE -ne 0) {
                throw "生成CA私钥失败"
            }
            Write-ColorOutput Green "✓ CA私钥生成完成"
        } catch {
            Write-ColorOutput Red "错误: $_"
            Read-Host "按 Enter 键退出"
            exit 1
        }
    } else {
        Write-ColorOutput Yellow "CA私钥已存在,跳过生成"
    }
    
    # 生成CA自签名证书(如果不存在)
    if (-not (Test-Path "ca.crt")) {
        Write-ColorOutput Cyan "正在生成CA自签名证书..."
        try {
            openssl req -new -x509 -days $DAYS_VALID -key private/ca.key -out ca.crt -config $OPENSSL_CONF `
                -subj "/C=$COUNTRY/ST=$STATE/L=$LOCALITY/O=$ORGANIZATION/OU=$ORGUNIT/CN=$COMMONNAME/emailAddress=$EMAIL" `
                -passin pass:$CA_PASSWORD
            if ($LASTEXITCODE -ne 0) {
                throw "生成CA证书失败"
            }
            Write-ColorOutput Green "✓ CA证书生成完成"
        } catch {
            Write-ColorOutput Red "错误: $_"
            Read-Host "按 Enter 键退出"
            exit 1
        }
    } else {
        Write-ColorOutput Yellow "CA证书已存在,跳过生成"
    }
    
    # 生成服务器私钥
    Write-ColorOutput Cyan "正在生成服务器私钥..."
    try {
        openssl genrsa -out private/server.key $KEY_SIZE
        if ($LASTEXITCODE -ne 0) {
            throw "生成服务器私钥失败"
        }
        Write-ColorOutput Green "✓ 服务器私钥生成完成"
    } catch {
        Write-ColorOutput Red "错误: $_"
        Read-Host "按 Enter 键退出"
        exit 1
    }
    
    # 生成证书签名请求(CSR)
    Write-ColorOutput Cyan "正在生成证书签名请求..."
    try {
        openssl req -new -key private/server.key -out certs/server.csr -config $OPENSSL_CONF `
            -subj "/C=$COUNTRY/ST=$STATE/L=$LOCALITY/O=$ORGANIZATION/OU=$ORGUNIT/CN=$COMMONNAME/emailAddress=$EMAIL" `
            -passin pass:$CA_PASSWORD
        if ($LASTEXITCODE -ne 0) {
            throw "生成CSR失败"
        }
        Write-ColorOutput Green "✓ CSR生成完成"
    } catch {
        Write-ColorOutput Red "错误: $_"
        Read-Host "按 Enter 键退出"
        exit 1
    }
    
    # 使用CA签名证书
    Write-ColorOutput Cyan "正在使用CA签名证书..."
    try {
        openssl ca -batch -config $OPENSSL_CONF -days $DAYS_VALID -in certs/server.csr -out certs/server.crt -keyfile private/ca.key -cert ca.crt -passin pass:$CA_PASSWORD
        if ($LASTEXITCODE -ne 0) {
            throw "签名证书失败"
        }
        Write-ColorOutput Green "✓ 证书签名完成"
    } catch {
        Write-ColorOutput Red "错误: $_"
        Read-Host "按 Enter 键退出"
        exit 1
    }
    
    # 生成PKCS#12格式证书
    Write-ColorOutput Cyan "正在生成PKCS#12格式证书..."
    try {
        openssl pkcs12 -export -out certs/server_with_password.p12 -inkey private/server.key -in certs/server.crt -certfile ca.crt -passout pass:$PKCS12_PASS
        if ($LASTEXITCODE -ne 0) {
            throw "生成PKCS#12证书失败"
        }
        Write-ColorOutput Green "✓ PKCS#12证书生成完成"
    } catch {
        Write-ColorOutput Red "错误: $_"
        Read-Host "按 Enter 键退出"
        exit 1
    }
    
    # 方法2:从 PEM 格式重新导出 PFX
    Write-ColorOutput Cyan "正在从 PEM 格式重新导出 PFX..."
    try {
        openssl pkcs12 -export -out certs/server_certificate.pfx `
            -inkey private/server.key `
            -in certs/server.crt `
            -certfile ca.crt `
            -passout pass:$PKCS12_PASS
        if ($LASTEXITCODE -ne 0) {
            throw "从 PEM 格式重新导出 PFX失败"
        }
        Write-ColorOutput Green "✓ 从 PEM 格式重新导出 PFX完成"
    } catch {
        Write-ColorOutput Red "错误: $_"
        Read-Host "按 Enter 键退出"
        exit 1
    }
    
    
    # 显示生成结果
    Write-Host ""
    Write-ColorOutput Cyan "=========================================="
    Write-ColorOutput Cyan "证书生成完成!"
    Write-ColorOutput Cyan "=========================================="
    Write-Host "生成的文件:"
    Write-Host "  - CA证书: ca.crt"
    Write-Host "  - CA私钥: private/ca.key"
    Write-Host "  - 服务器证书: certs/server.crt"
    Write-Host "  - 服务器私钥: private/server.key"
    Write-Host "  - 证书签名请求: certs/server.csr"
    if (Test-Path "certs/server_with_password.p12") {
        Write-Host "  - PKCS#12证书: certs/server_with_password.p12"
    }
    Write-Host "  - 签名证书: certs/server_certificate.pfx"
    Write-Host ""
    Write-ColorOutput Yellow "请妥善保管私钥文件,不要泄露给他人!"
    Write-Host ""
    
    Read-Host "按 Enter 键退出"
  3. 生成证书

每次运行都会重新生成证书

更多推荐