Skip to content

convert —— 转换证书格式 ​

在本地转换证书文件的编码格式,支持 PEM / DER / PFX / JKS 互转。纯本地命令,不联网。

用法 ​

bash
certiman convert [cert-file] [flags]

参数 ​

参数 / flag短名类型默认说明
[cert-file]string位置参数:源证书文件路径
--domain-d[]string选择器:从本机证书库中选择源证书
--conf-cstring选择器
--private-keystring私钥文件路径;PEM → PFX/JKS 时必填
--fromstring源格式:pem / pfx / jks;未提供时按扩展名推断
--tostring目标格式:pem / der / pfx / jks
--out-filestring单产物输出路径
--out-dirstring多产物输出目录
--password-filestring源密钥库口令文件
--target-password-filestring目标密钥库口令文件;未提供时与源口令相同
--jks-aliasstringJKS 别名
--pfx-encodingstringmodernPFX 编码:modern(默认,AES-256,OpenSSL 3.x 原生可读)/ legacy(3DES+SHA1,兼容 Windows 导入向导、JDK 8u301 之前的旧版环境)

密钥库保护强度提示

生成 PFX / JKS 时,以下三种情况下 CertiMan 输出一条警告(不中断转换):

  • 口令为空:任何获得该文件的人都能读取私钥
  • JKS:JKS 内置的口令保护算法为 SHA1,无法抵御离线暴力破解,请按「未加密副本」的标准保管
  • 国密 PFX(SM2):加密算法为 40-bit RC2,同样应按「未加密副本」的标准保管

需要加密保护时,请另行采用磁盘加密或传输层加密。

示例 ​

bash
# PEM → PFX(Windows/IIS 常用)
certiman convert -d example.com \
                 --to pfx \
                 --out-file ./example.com.pfx \
                 --target-password-file ./pfx.pass

# PEM → JKS(Java 应用)
certiman convert -d example.com \
                 --to jks \
                 --jks-alias example \
                 --out-file ./example.com.jks \
                 --target-password-file ./jks.pass

# 独立文件之间转换(不依赖本机证书库)
certiman convert ./cert.pem \
                 --private-key ./privkey.pem \
                 --to pfx \
                 --out-file ./cert.pfx \
                 --target-password-file ./pfx.pass

国密(SM2)双证的转换 ​

国密产品的一张订单签发两张证书:签名证书与加密证书。使用选择器(-d / -c)转换时, CertiMan 为两组证书分别生成产物,加密组的文件名在扩展名之前加 -enc:

bash
certiman convert -d example.com --to pfx --out-dir ./out \
                 --target-password-file ./pfx.pass
# ✔ 已写入 ./out/cert.pfx      —— 签名组
# ✔ 已写入 ./out/cert-enc.pfx  —— 加密组

国密双证书不支持 --out-file

--out-file 只能输出一份产物,对国密双证书使用时报错并提示改用 --out-dir(退出码 2)。只需要其中一组时,显式指定源文件:

bash
certiman convert ./certs/example.com/enc-cert.pem \
                 --private-key ./certs/example.com/enc-privkey.pem \
                 --to pfx --out-file ./enc.pfx --target-password-file ./pfx.pass

国密 PFX 的两个限制

国密 PKCS#12 仅支持 legacy 编码,--pfx-encoding modern 不生效;国密 PFX 不包含中间链,中间链通过 chain.pem 单独交付。

输出 ​

0成功(示例)
text
✔ 已写入 ./example.com.pfx
0JSON 输出
json
{
  "format": "pfx",
  "artifacts": ["./example.com.pfx"],
  "pfx_encoding_effective": "modern"
}

相关命令 ​

  • download —— 下载时通过 --format 直接生成目标格式
  • issue —— 申请时通过 --output.formats 指定每次交付生成的格式