8

我正在编写一个 Windows 服务,它需要证书存储中的多个证书才能连接到第三方 Web 服务。

在我的安装程序上,我调用了一个小型应用程序 (C#),它创建了一个用户来运行服务。

它工作正常。

我现在需要在用户证书存储中安装大约 10 个证书(不要问!),但找不到任何简洁的编程方式来做到这一点。

有什么提示吗?或者我将不得不使用COM互操作...

4

1 回答 1

12

原来你首先需要模拟用户。

使用A small C# Class for impersonating a User中描述的非常好的库,您可以执行以下操作:

using (new Impersonator("username", "", "password"))
{
    try
    {
        X509Store serviceRuntimeUserCertificateStore = new X509Store(StoreName.My);
        string baseDir = AppDomain.CurrentDomain.BaseDirectory;
        string certPath = Path.Combine(baseDir, certificateFolder);

        string certificateFile = "c:\\file.cert";
        string certificatePassword = "somePassword";
        string certificateLocation = certPath + "\\" + certificateFile;

        InstallCertificate(certificateLocation, certificatePassword);
    }
    catch (Exception ex)
    {
        Console.WriteLine(ex);
    }
}

private static void InstallCertificate(string certificatePath, string certificatePassword)
{
    try
    {
        var serviceRuntimeUserCertificateStore = new X509Store(StoreName.My);
        serviceRuntimeUserCertificateStore.Open(OpenFlags.ReadWrite);

        X509Certificate2 cert;

        try
        {
            cert = new X509Certificate2(certificatePath, certificatePassword);
        }
        catch(Exception ex)
        {
            Console.WriteLine("Failed to load certificate " + certificatePath);
            throw new DataException("Certificate appeared to load successfully but also seems to be null.", ex);
        }

        serviceRuntimeUserCertificateStore.Add(cert);
        serviceRuntimeUserCertificateStore.Close();
    }
    catch(Exception)
    {
        Console.WriteLine("Failed to install {0}.  Check the certificate index entry and verify the certificate file exists.", certificatePath);
    }
}

请添加您自己的异常处理。如果您要添加多个证书,请保持 X509Store 保持打开状态以提高效率。

于 2008-11-24T10:56:43.660 回答