如何使用 PowerShell 获取网站 SSL 证书的有效期?
powershellmicrosoft technologiessoftware & coding
SSL 证书是网站的重要组成部分。它们通过激活 HTTPS 安全连接,在客户端和服务器端的信息交换中发挥着关键作用。在下面的文章中,我们将使用 PowerShell 获取证书的有效期(起始日期和到期日期)。
为此,我们需要发起一个 HTTP Web 请求,但在此之前,我们将使用以下命令忽略 SSL 警告。
[Net.ServicePointManager]::ServerCertificateValidationCallback = { $true }
然后,我们将通过调用一个 .NET 类来发起 HTTP Web 请求。
$url = "https://www.microsoft.com/" $req = [Net.HttpWebRequest]::Create($url)
当我们检查 $req 时,会显示一些属性,但由于我们只对证书日期感兴趣,因此我们将使用特定的属性 ServicePoint 来检索相关信息。
$req.ServicePoint
上述命令的输出。
PS C:\WINDOWS\system32> $req.ServicePoint BindIPEndPointDelegate : ConnectionLeaseTimeout : -1 Address : https://www.microsoft.com/ MaxIdleTime : 100000 UseNagleAlgorithm : True ReceiveBufferSize : -1 Expect100Continue : True IdleSince : 23-06-2020 07:02:36 ProtocolVersion : 1.1 ConnectionName : https ConnectionLimit : 2 CurrentConnections : 0 Certificate : ClientCertificate : SupportsPipelining : True
如上所示,证书字段为空,因此我们需要使用GetResponse()方法来检索信息。
$req.GetResponse()
上述命令的输出。
IsMutuallyAuthenticated : False
Cookies : {}
Headers : {Pragma, X-Activity-Id, MS-CV, X-AppVersion...}
SupportsHeaders : True
ContentLength : -1
ContentEncoding :
ContentType : text/html; charset=utf-8
CharacterSet : utf-8
Server :
LastModified : 23-06-2020 07:06:44
StatusCode : OK
StatusDescription : OK
ProtocolVersion : 1.1
ResponseUri : https://www.microsoft.com/en-in/
Method : GET
IsFromCache : False
现在,我们将运行之前的命令,并检查是否能够检索到证书信息。
PS C:\WINDOWS\system32> $req.ServicePoint BindIPEndPointDelegate : ConnectionLeaseTimeout : -1 Address : https://www.microsoft.com/en-in/ MaxIdleTime : 100000 UseNagleAlgorithm : True ReceiveBufferSize : -1 Expect100Continue : True IdleSince : 23-06-2020 07:06:44 ProtocolVersion : 1.1 ConnectionName : https ConnectionLimit : 2 CurrentConnections : 1 Certificate : System.Security.Cryptography.X509Certificates.X509Cer tificate ClientCertificate : SupportsPipelining : True
是的,我们可以检索证书信息。如果 GetResponse() 命令抛出异常,您可以使用 try/catch 块,我会在最终脚本中使用它。但目前,我们只想检索证书日期。
$req.ServicePoint.Certificate
您将看到如下所示的输出。

上面的输出仍然缺少日期,因此我们将检查是否有任何属性或方法可以检索日期。我们将检查 Date 的可用属性和方法。
$req.ServicePoint.Certificate | gm | where{$_.Name -like "*Date*"}
TypeName: System.Security.Cryptography.X509Certificates.X509Certificate
Name MemberType Definition
---- ---------- ----------
GetEffectiveDateString Method string GetEffectiveDateString() GetExpirationDateString Method string GetExpirationDateString()
这里我们提供了获取证书生效日期和失效日期的两种方法。
生效日期
PS C:\WINDOWS\system32> $req.ServicePoint.Certificate.GetEffectiveDateString() 24-06-2019 06:25:35
失效日期
PS C:\WINDOWS\system32> $req.ServicePoint.Certificate.GetExpirationDateString() 22-10-2021 03:34:04
完整的脚本如下所示。
[Net.ServicePointManager]::ServerCertificateValidationCallback = { $true }
$url = "https://www.microsoft.com/"
$req = [Net.HttpWebRequest]::Create($url)
$req.GetResponse() | Out-Null
$output = [PSCustomObject]@{
URL = $url
'Cert Start Date' = $req.ServicePoint.Certificate.GetEffectiveDateString()
'Cert End Date' = $req.ServicePoint.Certificate.GetExpirationDateString()
}
$output
URL Cert Start Date Cert End Date
--- --------------- -------------
https://www.microsoft.com/ 26-06-2019 09:10:38 22-10-2021 03:34:04

