The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
List store locationsGet-ChildItem Cert:\View examples
List user personal certificatesGet-ChildItem Cert:\CurrentUser\MyView examples
Find expiring certificatesGet-ChildItem Cert:\LocalMachine\My -ExpiringInDays 30View examples
Find code-signing certificatesGet-ChildItem Cert:\CurrentUser\My -CodeSigningCertView examples
Select exact thumbprintGet-Item Cert:\CurrentUser\My\THUMBPRINTView examples
Inspect certificate details$certificate | Format-List Subject, Issuer, Thumbprint, NotBefore, NotAfter, HasPrivateKey, EnhancedKeyUsageListView examples
Build a certificate chain$chain.Build($certificate)View examples
Preview certificate importImport-Certificate -FilePath '.\issuer.cer' ` -CertStoreLocation Cert:\CurrentUser\Root -WhatIfView examples
Import private-key packageImport-PfxCertificate -FilePath '.\signing.pfx' ` -CertStoreLocation Cert:\CurrentUser\My -Password ` $passwordView examples
Export public certificateExport-Certificate -Cert $certificate -FilePath ` '.\signer.cer'View examples
Inspect a file signatureGet-AuthenticodeSignature -LiteralPath '.\Deploy.ps1'View examples
Sign with timestampSet-AuthenticodeSignature -LiteralPath '.\Deploy.ps1' ` -Certificate $certificate -TimestampServer ` 'http://timestamp.example' -HashAlgorithm SHA256View examples
Hash the final fileGet-FileHash -LiteralPath '.\Deploy.ps1' -Algorithm ` SHA256View examples
Preview certificate removalRemove-Item Cert:\CurrentUser\My\THUMBPRINT -WhatIfView examples

A certificate binds a public key to an identity under a trust chain; possession of its private key enables the represented operation. Resolve certificates by store, subject, issuer, enhanced key use, validity, and thumbprint—not friendly name alone. Protect private keys, distinguish test self-signing from production trust, and verify signatures and chains on the target systems.

Step by step

Detailed examples

01

Distinguish current-user and machine trust contexts

Cert: exposes CurrentUser and LocalMachine locations and stores such as My, Root, and CA. LocalMachine changes affect all users and normally require elevation. Store names express purpose, not proof that every contained certificate is trustworthy for every application.

Inventory personal stores without exposing private keys
Get-ChildItem Cert:\CurrentUser\My | Select-Object Subject, Issuer, Thumbprint, NotAfter, HasPrivateKey
Get-ChildItem Cert:\LocalMachine\My | Select-Object Subject, Issuer, Thumbprint, NotAfter, HasPrivateKey
Back to quick reference ↑
02

Resolve by full identity, purpose, and validity window

Friendly names and subjects are not unique. Check issuer, serial number, thumbprint, NotBefore/NotAfter, SAN/DNS names, enhanced key usage, key algorithm, and private-key presence. Expiry filters can include certificates with broad or empty EKU, so inspect intended purpose rather than relying on one switch.

Review code-signing candidates
Get-ChildItem Cert:\CurrentUser\My -CodeSigningCert |
  Where-Object NotAfter -gt (Get-Date) |
  Select-Object Subject, Issuer, Thumbprint, NotBefore, NotAfter, HasPrivateKey, EnhancedKeyUsageList
Back to quick reference ↑
03

Validate chains under the intended policy and time

A chain build uses local trust, revocation availability, verification time, and application policy. A successful cryptographic signature does not prove the signer is trusted or authorized. Inspect every ChainStatus entry and test on representative clean hosts where intermediate certificates and network access differ.

Build and report a chain
$certificate = Get-Item 'Cert:\CurrentUser\My\THUMBPRINT'
$chain = [System.Security.Cryptography.X509Certificates.X509Chain]::new()
$valid = $chain.Build($certificate)
[pscustomobject]@{ Valid = $valid; Subject = $certificate.Subject; Thumbprint = $certificate.Thumbprint }
$chain.ChainStatus | Format-Table Status, StatusInformation
Back to quick reference ↑
04

Separate public certificates from private-key packages

CER exports public material; PFX/PKCS#12 can contain private keys and certificate chains. Importing into Root grants trust and has a much larger security impact than importing into My. Obtain SecureString passwords interactively or through approved secret handling, restrict PFX files, and delete staging copies securely according to policy.

Preview public trust import and inspect PFX metadata
Import-Certificate -FilePath '.\issuer.cer' -CertStoreLocation 'Cert:\CurrentUser\Root' -WhatIf
$password = Read-Host 'PFX password' -AsSecureString
# After validating provenance and destination:
# Import-PfxCertificate -FilePath '.\signing.pfx' -CertStoreLocation 'Cert:\CurrentUser\My' -Password $password
Back to quick reference ↑
05

Sign final bytes and verify status independently

Any file change after signing invalidates the signature. The certificate needs code-signing EKU and an accessible private key. A trusted timestamp can preserve validity after signer expiry according to policy; use an approved timestamp service and SHA-256 or stronger policy. Verify Status, signer chain, and file hash in CI and on deployment targets.

Verify a signed script
$path = '.\Deploy.ps1'
$signature = Get-AuthenticodeSignature -LiteralPath $path
$signature | Format-List Status, StatusMessage, SignerCertificate, TimeStamperCertificate
Get-FileHash -LiteralPath $path -Algorithm SHA256
Back to quick reference ↑
06

Treat private-key access as the critical asset

HasPrivateKey does not prove the current identity can use the key. Machine keys have separate ACLs and service identities need narrowly granted access. Prefer non-exportable hardware-backed keys for high-value signing, audit use, rotate before expiry, and revoke compromised certificates. Certificate removal and private-key deletion are separate consequences in provider operations.

Record exact target before removal
$thumbprint = 'THUMBPRINT'
$certificate = Get-Item "Cert:\CurrentUser\My\$thumbprint"
$certificate | Format-List Subject, Issuer, Thumbprint, NotAfter, HasPrivateKey
Remove-Item "Cert:\CurrentUser\My\$thumbprint" -WhatIf
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoftabout_Certificate_Providerlearn.microsoft.com
  2. MicrosoftGet-AuthenticodeSignaturelearn.microsoft.com
  3. MicrosoftSet-AuthenticodeSignaturelearn.microsoft.com
  4. MicrosoftImport-PfxCertificatelearn.microsoft.com
  5. MicrosoftX509Chain Classlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback