New-EntraApplicationKeyCredential
為應用程式建立一個金鑰憑證。
語法
Default (預設值)
New-EntraApplicationKeyCredential
-ApplicationId <String>
[-CustomKeyIdentifier <String>]
[-Type <KeyType>]
[-Usage <KeyUsage>]
[-Value <String>]
[-EndDate <DateTime>]
[-StartDate <DateTime>]
[<CommonParameters>]
Description
New-EntraApplicationKeyCredential這個 cmdlet 會為應用程式建立一個金鑰憑證。
應用程式可以使用此指令 Remove-EntraApplicationKeyCredential 來自動擲出其過期金鑰。
作為請求驗證的一部分,必須驗證持有現有金鑰的證據,然後才能執行該動作。
範例
範例 1:建立新的應用程式金鑰憑證
Connect-Entra -Scopes 'Application.ReadWrite.All','Application.ReadWrite.OwnedBy'
$application = Get-EntraApplication -Filter "DisplayName eq 'Contoso Helpdesk Application'"
$params = @{
ApplicationId = $application.Id
CustomKeyIdentifier = 'EntraPowerShellKey'
StartDate = '2024-03-21T14:14:14Z'
Type = 'Symmetric'
Usage = 'Sign'
Value = '<my-value>'
}
New-EntraApplicationKeyCredential @params
CustomKeyIdentifier : {84, 101, 115, 116}
EndDate : 2024-03-21T14:14:14Z
KeyId : aaaaaaaa-0b0b-1c1c-2d2d-333333333333
StartDate : 2025-03-21T14:14:14Z
Type : Symmetric
Usage : Sign
Value : {49, 50, 51}
此範例展示了如何建立應用程式金鑰憑證。
-
-ApplicationId指定應用程式的唯一識別碼 -
-CustomKeyIdentifier指定自訂金鑰 ID。 -
-StartDate指定金鑰作為 DateTime 物件有效的時間點。 -
-Type指定金鑰的類型。 -
-Usage指定金鑰的使用方式。 因為AsymmetricX509Cert的使用必須是Verify,而 的X509CertAndPassword使用必須是Sign。 -
-Value指定鍵值。
你可以用 Get-EntraApplication cmdlet 來取得應用程式的物件 ID。
範例 2:使用憑證來新增應用程式金鑰憑證
Connect-Entra -Scopes 'Application.ReadWrite.All','Application.ReadWrite.OwnedBy'
$application = Get-EntraApplication -Filter "DisplayName eq 'Contoso Helpdesk Application'"
$cer = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2 #create a new certificate object
$cer.Import('C:\Users\ContosoUser\appcert.cer')
$bin = $cer.GetRawCertData()
$base64Value = [System.Convert]::ToBase64String($bin)
$bin = $cer.GetCertHash()
$base64Thumbprint = [System.Convert]::ToBase64String($bin)
$keyid = [System.Guid]::NewGuid().ToString()
$params = @{
ApplicationId = $application.Id
CustomKeyIdentifier = $base64Thumbprint
Type = 'AsymmetricX509Cert'
Usage = 'Verify'
Value = $base64Value
StartDate = $cer.GetEffectiveDateString()
EndDate = $cer.GetExpirationDateString()
}
New-EntraApplicationKeyCredential @params
此範例展示了如何建立應用程式金鑰憑證。
-
-ApplicationId指定應用程式的唯一識別碼 -
-CustomKeyIdentifier指定自訂金鑰 ID。 -
-StartDate指定金鑰作為 DateTime 物件有效的時間點。 -
-EndDate指定 DateTime 物件中金鑰失效的時間點。 -
-Type指定金鑰的類型。 -
-Usage指定金鑰的使用方式。 因為AsymmetricX509Cert的使用必須是Verify,而 的X509CertAndPassword使用必須是Sign。 -
-Value指定鍵值。
參數
-ApplicationId
在 Microsoft Entra ID 中指定應用程式的唯一 ID。
參數屬性
| 類型: | System.String |
| 預設值: | None |
| 支援萬用字元: | False |
| 不要顯示: | False |
| 別名: | ObjectId (物件識別碼) |
參數集
(All)
| Position: | Named |
| 必要: | True |
| 來自管線的值: | True |
| 來自管線按屬性名稱的值: | True |
| 來自剩餘引數的值: | False |
-CustomKeyIdentifier
指定自訂金鑰 ID。
參數屬性
| 類型: | System.String |
| 預設值: | None |
| 支援萬用字元: | False |
| 不要顯示: | False |
參數集
(All)
| Position: | Named |
| 必要: | False |
| 來自管線的值: | True |
| 來自管線按屬性名稱的值: | True |
| 來自剩餘引數的值: | False |
-EndDate
指定 DateTime 物件中金鑰失效的時間點。
參數屬性
| 類型: | System.DateTime |
| 預設值: | None |
| 支援萬用字元: | False |
| 不要顯示: | False |
參數集
(All)
| Position: | Named |
| 必要: | False |
| 來自管線的值: | True |
| 來自管線按屬性名稱的值: | True |
| 來自剩餘引數的值: | False |
-StartDate
指定金鑰作為 DateTime 物件有效的時間點。
參數屬性
| 類型: | System.DateTime |
| 預設值: | None |
| 支援萬用字元: | False |
| 不要顯示: | False |
參數集
(All)
| Position: | Named |
| 必要: | False |
| 來自管線的值: | True |
| 來自管線按屬性名稱的值: | True |
| 來自剩餘引數的值: | False |
-Type
指定金鑰的類型。
參數屬性
| 類型: | KeyType |
| 預設值: | None |
| 支援萬用字元: | False |
| 不要顯示: | False |
參數集
(All)
| Position: | Named |
| 必要: | False |
| 來自管線的值: | True |
| 來自管線按屬性名稱的值: | True |
| 來自剩餘引數的值: | False |
-Usage
指定金鑰的使用方式。
-
AsymmetricX509Cert: 用法必須為Verify。 -
X509CertAndPassword: 用法必須為Sign。
參數屬性
| 類型: | KeyUsage |
| 預設值: | None |
| 支援萬用字元: | False |
| 不要顯示: | False |
參數集
(All)
| Position: | Named |
| 必要: | False |
| 來自管線的值: | True |
| 來自管線按屬性名稱的值: | True |
| 來自剩餘引數的值: | False |
-Value
指定鍵值。
參數屬性
| 類型: | System.String |
| 預設值: | None |
| 支援萬用字元: | False |
| 不要顯示: | False |
參數集
(All)
| Position: | Named |
| 必要: | False |
| 來自管線的值: | True |
| 來自管線按屬性名稱的值: | True |
| 來自剩餘引數的值: | False |
CommonParameters
此 Cmdlet 支援一般參數:-Debug、-ErrorAction、-ErrorVariable、-InformationAction、-InformationVariable、-OutBuffer、-OutVariable、-PipelineVariable、-ProgressAction、-Verbose、-WarningAction 和 -WarningVariable。 如需詳細資訊,請參閱 about_CommonParameters。