Certificati / PKI
Creare una CSR, verificare un PFX, convertire formati, controllare le scadenze nell'archivio certificati.
Creare una CSR
Crea una richiesta di certificato e la chiave, con tutti i nomi aggiuntivi (SAN) per gli host di posta e Autodiscover.
Mail + Autodiscover
- Nome comune (CN)
-
mail.example.comModifica nel generatore → - Nomi aggiuntivi (SAN)
-
mail.example.com, autodiscover.example.comModifica nel generatore → - File della chiave
-
privkey.pemModifica nel generatore →
PowerShell (Windows)
certreq Integrato
@"
[NewRequest]
Subject = "CN=mail.example.com"
KeyLength = 2048
Exportable = TRUE
MachineKeySet = TRUE
[Extensions]
2.5.29.17 = "{text}dns=mail.example.com&dns=autodiscover.example.com"
"@ | Set-Content req.inf
certreq -new req.inf mail.example.com.csr openssl Strumento aggiuntivo
openssl req -new -newkey rsa:2048 -nodes -keyout privkey.pem -out mail.example.com.csr -subj "/CN=mail.example.com" -addext "subjectAltName=DNS:mail.example.com,DNS:autodiscover.example.com" Shell Unix (bash)
openssl Integrato
openssl req -new -newkey rsa:2048 -nodes -keyout privkey.pem -out mail.example.com.csr -subj "/CN=mail.example.com" -addext "subjectAltName=DNS:mail.example.com,DNS:autodiscover.example.com" certtool Strumento aggiuntivo
certtool --generate-privkey --outfile privkey.pem && certtool --generate-request --load-privkey privkey.pem --outfile mail.example.com.csr I browser e i server moderni valutano solo le voci SAN; il solo nome comune non basta più da anni. certreq salva la chiave nell'archivio certificati di Windows, openssl in un file.
Esaminare una CSR
Mostra il contenuto di una richiesta di certificato prima dell'invio alla CA: nomi, lunghezza della chiave e firma.
- Nome comune (CN)
-
mail.example.comModifica nel generatore →
PowerShell (Windows)
certutil Integrato
certutil -dump mail.example.com.csr openssl Strumento aggiuntivo
openssl req -in mail.example.com.csr -noout -text -verify Shell Unix (bash)
openssl Integrato
openssl req -in mail.example.com.csr -noout -subject -reqopt no_sigdump -text | head -20 certtool Strumento aggiuntivo
certtool --crq-info --infile mail.example.com.csr Esaminare un file PFX
Mostra soggetto, emittente, validità e catena di un file PFX/P12 e se la chiave privata è inclusa.
- File PFX
-
cert.pfxModifica nel generatore →
PowerShell (Windows)
Get-PfxData Integrato
$pw = Read-Host "PFX-Passwort" -AsSecureString
$d = Get-PfxData -FilePath "cert.pfx" -Password $pw
$d.EndEntityCertificates | Format-List Subject, Issuer, NotAfter, Thumbprint, HasPrivateKey
$d.OtherCertificates | ForEach-Object { $_.Subject } openssl Strumento aggiuntivo
openssl pkcs12 -in cert.pfx -nokeys -info | openssl x509 -noout -subject -issuer -dates Shell Unix (bash)
openssl Integrato
openssl pkcs12 -in cert.pfx -nokeys -legacy 2>/dev/null | openssl x509 -noout -subject -issuer -dates certtool Strumento aggiuntivo
certtool --p12-info --infile cert.pfx Per i file PFX più vecchi, OpenSSL 3 richiede l'opzione -legacy, altrimenti rifiuta il vecchio algoritmo RC2.
Convertire formati
Converte tra PFX/P12 e PEM (certificato e chiave separati): il passaggio più comune per spostare un certificato tra Windows e un'appliance.
- File PFX
-
cert.pfxModifica nel generatore → - File del certificato
-
cert.pemModifica nel generatore → - File della chiave
-
privkey.pemModifica nel generatore →
PowerShell (Windows)
certutil / Export-PfxCertificate Integrato
# PFX -> Base64-PEM (nur Zertifikat, ohne Schlüssel)
certutil -encode cert.pem.der cert.pem
# Zertifikat aus dem Store als PFX exportieren:
# Get-ChildItem Cert:\LocalMachine\My\<Thumbprint> | Export-PfxCertificate -FilePath cert.pfx -Password (Read-Host -AsSecureString) openssl Strumento aggiuntivo
openssl pkcs12 -in cert.pfx -clcerts -nokeys -out cert.pem
openssl pkcs12 -in cert.pfx -nocerts -nodes -out privkey.pem Shell Unix (bash)
openssl Integrato
openssl pkcs12 -in cert.pfx -clcerts -nokeys -out cert.pem
openssl pkcs12 -in cert.pfx -nocerts -nodes -out privkey.pem
openssl pkcs12 -export -in cert.pem -inkey privkey.pem -out neu.pfx certtool Strumento aggiuntivo
certtool --load-certificate cert.pem --load-privkey privkey.pem --to-p12 --outfile neu.p12 Il file della chiave generato non è cifrato. Eliminatelo dopo l'importazione e non lasciatelo su una condivisione di rete.
Chiave e certificato corrispondono?
Verifica se un file di chiave appartiene al certificato: un checksum identico significa che vanno insieme.
- File del certificato
-
cert.pemModifica nel generatore → - File della chiave
-
privkey.pemModifica nel generatore →
PowerShell (Windows)
X509Certificate2 Integrato
$c = New-Object Security.Cryptography.X509Certificates.X509Certificate2 "cert.pem"
"HasPrivateKey: $($c.HasPrivateKey)"
$c.PublicKey.Key.ToXmlString($false).Substring(0, 60) openssl Strumento aggiuntivo
openssl x509 -in cert.pem -noout -modulus | openssl md5
openssl rsa -in privkey.pem -noout -modulus | openssl md5 Shell Unix (bash)
openssl Integrato
openssl x509 -in cert.pem -noout -modulus | openssl sha256
openssl rsa -in privkey.pem -noout -modulus | openssl sha256
# Gleiche Prüfsumme = Schlüssel und Zertifikat gehören zusammen. certtool Strumento aggiuntivo
certtool --certificate-info --infile cert.pem | grep -A2 "Public Key ID" Questo scambio è la causa più frequente di "il certificato non può essere importato".
Esaminare l'archivio certificati
Elenca i certificati installati con impronta, soggetto e scadenza.
- Impronta (thumbprint)
-
A1B2C3D4E5F6A7B8C9D0E1F2A3B4C5D6E7F8A9B0Modifica nel generatore →
PowerShell (Windows)
Cert: PSDrive Integrato
Get-ChildItem Cert:\LocalMachine\My | Sort-Object NotAfter |
Format-Table Thumbprint, Subject, NotAfter, HasPrivateKey -AutoSize
Get-Item Cert:\LocalMachine\My\A1B2C3D4E5F6A7B8C9D0E1F2A3B4C5D6E7F8A9B0 | Format-List * certutil Integrato
certutil -store My Shell Unix (bash)
ls / openssl Integrato
ls -1 /etc/ssl/certs | head -20
awk -v cmd='openssl x509 -noout -subject -enddate' '/BEGIN/{close(cmd)};{print | cmd}' /etc/ssl/certs/ca-certificates.crt | head -20 trust Strumento aggiuntivo
trust list --filter=ca-anchors | head -40 Su Windows l'impronta è l'identificatore con cui Exchange e IIS associano un certificato.
Che cosa scade a breve?
Trova i certificati che scadono nei prossimi 60 giorni: il controllo che evita un'interruzione nel fine settimana.
PowerShell (Windows)
Cert: PSDrive Integrato
Get-ChildItem Cert:\LocalMachine\My |
Where-Object { $_.NotAfter -lt (Get-Date).AddDays(60) } |
Sort-Object NotAfter |
Format-Table Subject, NotAfter, Thumbprint -AutoSize certutil Strumento aggiuntivo
certutil -store My | findstr /C:"NotAfter" Shell Unix (bash)
openssl Integrato
for c in /etc/ssl/certs/*.pem; do
openssl x509 -in "$c" -noout -checkend 5184000 >/dev/null 2>&1 || echo "laeuft bald ab: $c"
done certtool Strumento aggiuntivo
certtool --certificate-info --infile /etc/ssl/certs/ssl-cert-snakeoil.pem | grep -E "Not After"