使用 StyleBook 从证书存储管理 SSL 证书

Last published : Oct 06, 2026
NetScaler Console 证书存储可帮助您在一个位置存储和管理 SSL 证书。因此,您可以将 SSL 证书存储在 NetScaler Console 中,并在 NetScaler 配置期间重复使用它们。
本文介绍如何创建 StyleBook 定义,以便从 NetScaler Console 证书存储上传和重复使用 SSL 证书。

参数

的 StyleBook 定义支持 certkey 作为新的内置参数类型。使用此参数类型可从 NetScaler Console 证书存储中重复使用 SSL 证书。
parameters:
-
    name: certificate
    label: Certificate
    description: "Certificate to be bound to this virtual load balanced application"
    type: certkey
    required: true
在此示例中,证书参数指 NetScaler Console 证书存储中的 SSL 证书或证书链。
在 StyleBook 定义中,您可以引用 certkey 参数的以下属性:
  • certkeyname – 您要在实例上配置的 SSL 证书密钥的名称。
  • cert_filename – SSL 证书的文件名。
  • password – 必要时访问 SSL 证书所需的密码。
  • key_filename – SSL 证书密钥的文件名。
  • keyfile_contents – SSL 证书的文件内容。
  • subject – SSL 证书中提及的主题。
  • issuer – 它指颁发 SSL 证书的机构。
  • certchain_certkeyname – 有时,服务器证书由多个分层证书颁发机构 (CA) 签名,这意味着这些证书形成一个链。
    当证书存储区包含证书链时,请使用此属性。它有助于您引用和绑定证书。创建配置包时,证书链将显示为列表。
这些属性可帮助您在 StyleBook 定义中创建所需的组件。

组件

当 StyleBook 具有 type: certkey 参数时,StyleBook 用户可以从 NetScaler Console 证书存储区为此参数提供证书。在此工作流程中,除了从 NetScaler Console 证书存储区查看和选择证书外,用户还可以执行以下操作:
  • 上传新证书。
  • 更新现有证书。例如,已过期的证书。
  • 删除证书。
注意
  • 您还可以使用 NetScaler Console SSL 控制板管理 NetScaler Console 证书存储区中的证书。
  • 当 NetScaler Console 证书存储区中的 SSL 证书更新时,与该 SSL 证书关联的配置包将自动更新。

构建您的 StyleBook

以下是 StyleBook 定义示例。这是一个完整的定义,它使用来自 NetScaler Console 证书存储区的 SSL 证书。此 StyleBook 包含将主证书和密钥文件上传到 NetScaler 实例的组件。如果这些文件已存在于 NetScaler 实例上,NetScaler Console 将跳过上传步骤,并且这些组件将不起作用。
name: lb-with-cert-from-certstore
namespace: com.example.stylebooks
version: "1.0"
display-name: Application using a CertStore certificate
description: This StyleBook defines a simple SSL Vserver.
schema-version: "1.0"

import-stylebooks:
 -
    namespace: netscaler.nitro.config
    version: "13.0"
    prefix: ns

parameters:
 -
  name: name
  type: string
  label: Application Name
  description: Give a name to the application configuration.
  required: true
 -
  name: ip
  type: ipaddress
  label: Application Virtual IP (VIP)
  description: The Application VIP that clients access
  required: true
 -
  name: certificate
  label: Application Certificate
  description: Certificate chain and key to be bound to this application
  type: certkey
  required: true


components:
 -
    name: pem-cert-files-comp
    type: ns::systemfile
    description: This component uploads the PEM certificate file onto the NetScaler
    condition: $parameters.certificate
    properties:
      filename: $parameters.certificate.cert_filename
      filelocation: /nsconfig/ssl
      filecontent: base64($parameters.certificate.certfile_contents)
      fileencoding: BASE64
 -
    name: pem-KEY-files-comp
    type: ns::systemfile
    description: This component uploads the PEM key file onto the NetScaler.
    condition: $parameters.certificate
    properties:
      filename: $parameters.certificate.key_filename
      filelocation: /nsconfig/ssl
      filecontent: base64($parameters.certificate.keyfile_contents)
      fileencoding: BASE64
 -
    name: cert-files-comp
    type: ns::sslcertkey
    description: This component creates the certkey on the NetScaler using the uploaded files.
    condition: $parameters.certificate
    properties:
      certkey:  $parameters.certificate.certkeyname
      cert: $parameters.certificate.cert_filename
      key: $parameters.certificate.key_filename
 -
  name: lbvserver-comp
  type: ns::lbvserver
  description: This component creates the lbvserver of the application.
  properties:
   name: $parameters.name + "-lbvserver"
   servicetype: SSL
   ipv46: $parameters.ip
   port: 443
   lbmethod: ROUNDROBIN
  components:
      -
        name: sslvserver-comp
        type: ns::sslvserver
        description: This component configures SSL settings on the vserver
        properties:
          vservername: $parent.properties.name
          ssl3?: ENABLED
          tls1?: ENABLED
          tls11?: ENABLED
      -
       name: cert-bindings-adv-comp
       type: ns::sslvserver_sslcertkey_binding
       description: This component binds the certkey to the vserver
       condition: $parameters.certificate
       properties:
         vservername: $parent.properties.name
         certkeyname: $parameters.certificate.certkeyname