The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| List store locations | Get-ChildItem Cert:\ | View examples |
| List user personal certificates | Get-ChildItem Cert:\CurrentUser\My | View examples |
| Find expiring certificates | Get-ChildItem Cert:\LocalMachine\My -ExpiringInDays 30 | View examples |
| Find code-signing certificates | Get-ChildItem Cert:\CurrentUser\My -CodeSigningCert | View examples |
| Select exact thumbprint | Get-Item Cert:\CurrentUser\My\THUMBPRINT | View examples |
| Inspect certificate details | $certificate |
Format-List Subject, Issuer, Thumbprint, NotBefore, NotAfter, HasPrivateKey, EnhancedKeyUsageList | View examples |
| Build a certificate chain | $chain.Build($certificate) | View examples |
| Preview certificate import | Import-Certificate -FilePath '.\issuer.cer' `
-CertStoreLocation Cert:\CurrentUser\Root -WhatIf | View examples |
| Import private-key package | Import-PfxCertificate -FilePath '.\signing.pfx' `
-CertStoreLocation Cert:\CurrentUser\My -Password `
$password | View examples |
| Export public certificate | Export-Certificate -Cert $certificate -FilePath `
'.\signer.cer' | View examples |
| Inspect a file signature | Get-AuthenticodeSignature -LiteralPath '.\Deploy.ps1' | View examples |
| Sign with timestamp | Set-AuthenticodeSignature -LiteralPath '.\Deploy.ps1' `
-Certificate $certificate -TimestampServer `
'http://timestamp.example' -HashAlgorithm SHA256 | View examples |
| Hash the final file | Get-FileHash -LiteralPath '.\Deploy.ps1' -Algorithm `
SHA256 | View examples |
| Preview certificate removal | Remove-Item Cert:\CurrentUser\My\THUMBPRINT -WhatIf | View examples |
A certificate binds a public key to an identity under a trust chain; possession of its private key enables the represented operation. Resolve certificates by store, subject, issuer, enhanced key use, validity, and thumbprint—not friendly name alone. Protect private keys, distinguish test self-signing from production trust, and verify signatures and chains on the target systems.
Step by step
Detailed examples
Distinguish current-user and machine trust contexts
Cert: exposes CurrentUser and LocalMachine locations and stores such as My, Root, and CA. LocalMachine changes affect all users and normally require elevation. Store names express purpose, not proof that every contained certificate is trustworthy for every application.
Get-ChildItem Cert:\CurrentUser\My | Select-Object Subject, Issuer, Thumbprint, NotAfter, HasPrivateKey
Get-ChildItem Cert:\LocalMachine\My | Select-Object Subject, Issuer, Thumbprint, NotAfter, HasPrivateKey Resolve by full identity, purpose, and validity window
Friendly names and subjects are not unique. Check issuer, serial number, thumbprint, NotBefore/NotAfter, SAN/DNS names, enhanced key usage, key algorithm, and private-key presence. Expiry filters can include certificates with broad or empty EKU, so inspect intended purpose rather than relying on one switch.
Get-ChildItem Cert:\CurrentUser\My -CodeSigningCert |
Where-Object NotAfter -gt (Get-Date) |
Select-Object Subject, Issuer, Thumbprint, NotBefore, NotAfter, HasPrivateKey, EnhancedKeyUsageList Validate chains under the intended policy and time
A chain build uses local trust, revocation availability, verification time, and application policy. A successful cryptographic signature does not prove the signer is trusted or authorized. Inspect every ChainStatus entry and test on representative clean hosts where intermediate certificates and network access differ.
$certificate = Get-Item 'Cert:\CurrentUser\My\THUMBPRINT'
$chain = [System.Security.Cryptography.X509Certificates.X509Chain]::new()
$valid = $chain.Build($certificate)
[pscustomobject]@{ Valid = $valid; Subject = $certificate.Subject; Thumbprint = $certificate.Thumbprint }
$chain.ChainStatus | Format-Table Status, StatusInformation Separate public certificates from private-key packages
CER exports public material; PFX/PKCS#12 can contain private keys and certificate chains. Importing into Root grants trust and has a much larger security impact than importing into My. Obtain SecureString passwords interactively or through approved secret handling, restrict PFX files, and delete staging copies securely according to policy.
Import-Certificate -FilePath '.\issuer.cer' -CertStoreLocation 'Cert:\CurrentUser\Root' -WhatIf
$password = Read-Host 'PFX password' -AsSecureString
# After validating provenance and destination:
# Import-PfxCertificate -FilePath '.\signing.pfx' -CertStoreLocation 'Cert:\CurrentUser\My' -Password $password Sign final bytes and verify status independently
Any file change after signing invalidates the signature. The certificate needs code-signing EKU and an accessible private key. A trusted timestamp can preserve validity after signer expiry according to policy; use an approved timestamp service and SHA-256 or stronger policy. Verify Status, signer chain, and file hash in CI and on deployment targets.
$path = '.\Deploy.ps1'
$signature = Get-AuthenticodeSignature -LiteralPath $path
$signature | Format-List Status, StatusMessage, SignerCertificate, TimeStamperCertificate
Get-FileHash -LiteralPath $path -Algorithm SHA256 Treat private-key access as the critical asset
HasPrivateKey does not prove the current identity can use the key. Machine keys have separate ACLs and service identities need narrowly granted access. Prefer non-exportable hardware-backed keys for high-value signing, audit use, rotate before expiry, and revoke compromised certificates. Certificate removal and private-key deletion are separate consequences in provider operations.
$thumbprint = 'THUMBPRINT'
$certificate = Get-Item "Cert:\CurrentUser\My\$thumbprint"
$certificate | Format-List Subject, Issuer, Thumbprint, NotAfter, HasPrivateKey
Remove-Item "Cert:\CurrentUser\My\$thumbprint" -WhatIf Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



