Creare una CSR

Crea una richiesta di certificato e la chiave, con tutti i nomi aggiuntivi (SAN) per gli host di posta e Autodiscover.

Mail + Autodiscover

PowerShell (Windows)

certreq Integrato

@"
[NewRequest]
Subject = "CN=mail.example.com"
KeyLength = 2048
Exportable = TRUE
MachineKeySet = TRUE
[Extensions]
2.5.29.17 = "{text}dns=mail.example.com&dns=autodiscover.example.com"
"@ | Set-Content req.inf
certreq -new req.inf mail.example.com.csr

openssl Strumento aggiuntivo

openssl req -new -newkey rsa:2048 -nodes -keyout privkey.pem -out mail.example.com.csr -subj "/CN=mail.example.com" -addext "subjectAltName=DNS:mail.example.com,DNS:autodiscover.example.com"

Shell Unix (bash)

openssl Integrato

openssl req -new -newkey rsa:2048 -nodes -keyout privkey.pem -out mail.example.com.csr -subj "/CN=mail.example.com" -addext "subjectAltName=DNS:mail.example.com,DNS:autodiscover.example.com"

certtool Strumento aggiuntivo

certtool --generate-privkey --outfile privkey.pem && certtool --generate-request --load-privkey privkey.pem --outfile mail.example.com.csr

I browser e i server moderni valutano solo le voci SAN; il solo nome comune non basta più da anni. certreq salva la chiave nell'archivio certificati di Windows, openssl in un file.

Esaminare una CSR

Mostra il contenuto di una richiesta di certificato prima dell'invio alla CA: nomi, lunghezza della chiave e firma.

PowerShell (Windows)

certutil Integrato

certutil -dump mail.example.com.csr

openssl Strumento aggiuntivo

openssl req -in mail.example.com.csr -noout -text -verify

Shell Unix (bash)

openssl Integrato

openssl req -in mail.example.com.csr -noout -subject -reqopt no_sigdump -text | head -20

certtool Strumento aggiuntivo

certtool --crq-info --infile mail.example.com.csr

Esaminare un file PFX

Mostra soggetto, emittente, validità e catena di un file PFX/P12 e se la chiave privata è inclusa.

PowerShell (Windows)

Get-PfxData Integrato

$pw = Read-Host "PFX-Passwort" -AsSecureString
$d = Get-PfxData -FilePath "cert.pfx" -Password $pw
$d.EndEntityCertificates | Format-List Subject, Issuer, NotAfter, Thumbprint, HasPrivateKey
$d.OtherCertificates | ForEach-Object { $_.Subject }

openssl Strumento aggiuntivo

openssl pkcs12 -in cert.pfx -nokeys -info | openssl x509 -noout -subject -issuer -dates

Shell Unix (bash)

openssl Integrato

openssl pkcs12 -in cert.pfx -nokeys -legacy 2>/dev/null | openssl x509 -noout -subject -issuer -dates

certtool Strumento aggiuntivo

certtool --p12-info --infile cert.pfx

Per i file PFX più vecchi, OpenSSL 3 richiede l'opzione -legacy, altrimenti rifiuta il vecchio algoritmo RC2.

Convertire formati

Converte tra PFX/P12 e PEM (certificato e chiave separati): il passaggio più comune per spostare un certificato tra Windows e un'appliance.

PowerShell (Windows)

certutil / Export-PfxCertificate Integrato

# PFX -> Base64-PEM (nur Zertifikat, ohne Schlüssel)
certutil -encode cert.pem.der cert.pem
# Zertifikat aus dem Store als PFX exportieren:
# Get-ChildItem Cert:\LocalMachine\My\<Thumbprint> | Export-PfxCertificate -FilePath cert.pfx -Password (Read-Host -AsSecureString)

openssl Strumento aggiuntivo

openssl pkcs12 -in cert.pfx -clcerts -nokeys -out cert.pem
openssl pkcs12 -in cert.pfx -nocerts -nodes -out privkey.pem

Shell Unix (bash)

openssl Integrato

openssl pkcs12 -in cert.pfx -clcerts -nokeys -out cert.pem
openssl pkcs12 -in cert.pfx -nocerts -nodes -out privkey.pem
openssl pkcs12 -export -in cert.pem -inkey privkey.pem -out neu.pfx

certtool Strumento aggiuntivo

certtool --load-certificate cert.pem --load-privkey privkey.pem --to-p12 --outfile neu.p12

Il file della chiave generato non è cifrato. Eliminatelo dopo l'importazione e non lasciatelo su una condivisione di rete.

Chiave e certificato corrispondono?

Verifica se un file di chiave appartiene al certificato: un checksum identico significa che vanno insieme.

PowerShell (Windows)

X509Certificate2 Integrato

$c = New-Object Security.Cryptography.X509Certificates.X509Certificate2 "cert.pem"
"HasPrivateKey: $($c.HasPrivateKey)"
$c.PublicKey.Key.ToXmlString($false).Substring(0, 60)

openssl Strumento aggiuntivo

openssl x509 -in cert.pem -noout -modulus | openssl md5
openssl rsa -in privkey.pem -noout -modulus | openssl md5

Shell Unix (bash)

openssl Integrato

openssl x509 -in cert.pem -noout -modulus | openssl sha256
openssl rsa -in privkey.pem -noout -modulus | openssl sha256
# Gleiche Prüfsumme = Schlüssel und Zertifikat gehören zusammen.

certtool Strumento aggiuntivo

certtool --certificate-info --infile cert.pem | grep -A2 "Public Key ID"

Questo scambio è la causa più frequente di "il certificato non può essere importato".

Esaminare l'archivio certificati

Elenca i certificati installati con impronta, soggetto e scadenza.

PowerShell (Windows)

Cert: PSDrive Integrato

Get-ChildItem Cert:\LocalMachine\My | Sort-Object NotAfter |
  Format-Table Thumbprint, Subject, NotAfter, HasPrivateKey -AutoSize
Get-Item Cert:\LocalMachine\My\A1B2C3D4E5F6A7B8C9D0E1F2A3B4C5D6E7F8A9B0 | Format-List *

certutil Integrato

certutil -store My

Shell Unix (bash)

ls / openssl Integrato

ls -1 /etc/ssl/certs | head -20
awk -v cmd='openssl x509 -noout -subject -enddate' '/BEGIN/{close(cmd)};{print | cmd}' /etc/ssl/certs/ca-certificates.crt | head -20

trust Strumento aggiuntivo

trust list --filter=ca-anchors | head -40

Su Windows l'impronta è l'identificatore con cui Exchange e IIS associano un certificato.

Che cosa scade a breve?

Trova i certificati che scadono nei prossimi 60 giorni: il controllo che evita un'interruzione nel fine settimana.

PowerShell (Windows)

Cert: PSDrive Integrato

Get-ChildItem Cert:\LocalMachine\My |
  Where-Object { $_.NotAfter -lt (Get-Date).AddDays(60) } |
  Sort-Object NotAfter |
  Format-Table Subject, NotAfter, Thumbprint -AutoSize

certutil Strumento aggiuntivo

certutil -store My | findstr /C:"NotAfter"

Shell Unix (bash)

openssl Integrato

for c in /etc/ssl/certs/*.pem; do
  openssl x509 -in "$c" -noout -checkend 5184000 >/dev/null 2>&1 || echo "laeuft bald ab: $c"
done

certtool Strumento aggiuntivo

certtool --certificate-info --infile /etc/ssl/certs/ssl-cert-snakeoil.pem | grep -E "Not After"

Altre aree