Appearance
convert —— 转换证书格式
在本地转换证书文件的编码格式,支持 PEM / DER / PFX / JKS 互转。纯本地命令,不联网。
用法
bash
certiman convert [cert-file] [flags]参数
| 参数 / flag | 短名 | 类型 | 默认 | 说明 |
|---|---|---|---|---|
[cert-file] | string | 位置参数:源证书文件路径 | ||
--domain | -d | []string | 选择器:从本机证书库中选择源证书 | |
--conf | -c | string | 选择器 | |
--private-key | string | 私钥文件路径;PEM → PFX/JKS 时必填 | ||
--from | string | 源格式:pem / pfx / jks;未提供时按扩展名推断 | ||
--to | string | 目标格式:pem / der / pfx / jks | ||
--out-file | string | 单产物输出路径 | ||
--out-dir | string | 多产物输出目录 | ||
--password-file | string | 源密钥库口令文件 | ||
--target-password-file | string | 目标密钥库口令文件;未提供时与源口令相同 | ||
--jks-alias | string | JKS 别名 | ||
--pfx-encoding | string | modern | PFX 编码:modern(默认,AES-256,OpenSSL 3.x 原生可读)/ legacy(3DES+SHA1,兼容 Windows 导入向导、JDK 8u301 之前的旧版环境) |
密钥库保护强度提示
生成 PFX / JKS 时,以下三种情况下 CertiMan 输出一条警告(不中断转换):
- 口令为空:任何获得该文件的人都能读取私钥
- JKS:JKS 内置的口令保护算法为 SHA1,无法抵御离线暴力破解,请按「未加密副本」的标准保管
- 国密 PFX(SM2):加密算法为 40-bit RC2,同样应按「未加密副本」的标准保管
需要加密保护时,请另行采用磁盘加密或传输层加密。
示例
bash
# PEM → PFX(Windows/IIS 常用)
certiman convert -d example.com \
--to pfx \
--out-file ./example.com.pfx \
--target-password-file ./pfx.pass
# PEM → JKS(Java 应用)
certiman convert -d example.com \
--to jks \
--jks-alias example \
--out-file ./example.com.jks \
--target-password-file ./jks.pass
# 独立文件之间转换(不依赖本机证书库)
certiman convert ./cert.pem \
--private-key ./privkey.pem \
--to pfx \
--out-file ./cert.pfx \
--target-password-file ./pfx.pass国密(SM2)双证的转换
国密产品的一张订单签发两张证书:签名证书与加密证书。使用选择器(-d / -c)转换时, CertiMan 为两组证书分别生成产物,加密组的文件名在扩展名之前加 -enc:
bash
certiman convert -d example.com --to pfx --out-dir ./out \
--target-password-file ./pfx.pass
# ✔ 已写入 ./out/cert.pfx —— 签名组
# ✔ 已写入 ./out/cert-enc.pfx —— 加密组国密双证书不支持 --out-file
--out-file 只能输出一份产物,对国密双证书使用时报错并提示改用 --out-dir(退出码 2)。只需要其中一组时,显式指定源文件:
bash
certiman convert ./certs/example.com/enc-cert.pem \
--private-key ./certs/example.com/enc-privkey.pem \
--to pfx --out-file ./enc.pfx --target-password-file ./pfx.pass国密 PFX 的两个限制
国密 PKCS#12 仅支持 legacy 编码,--pfx-encoding modern 不生效;国密 PFX 不包含中间链,中间链通过 chain.pem 单独交付。
