bitlocker不使用加密证书,而是依赖密钥保护器,其中恢复密钥(48位数字字符串)是唯一可导出且解密必需的凭证;可通过powershell批量导出已启用卷的恢复密钥到独立txt文件。
bitlocker 本身不使用“加密证书”这一概念,它依赖的是密钥保护器(key protectors),比如密码、tpm、恢复密码、数字证书(仅用于网络解锁场景,极少见)、或存储在 ad 中的恢复密钥。你提到的“导出加密证书”,大概率是指:
- 导出 BitLocker 恢复密钥(Recovery Password) —— 这是唯一可备份、可导出、且解密必需的凭证;
- 或误将 EFS(Encrypting File System)的用户证书当作 BitLocker 证书(二者完全不同,EFS 才用证书)。
BitLocker 不生成或管理 X.509 证书用于卷加密;它的恢复密钥是 48 位数字字符串(格式如:123456-789012-345678-901234-567890-123456-789012-345678),由系统生成并可导出为文本或 AD 备份。
所以,正确目标应是:
✅ 通过 PowerShell 批量导出所有已启用 BitLocker 的卷的恢复密钥
查看所有已加密卷及其恢复密钥状态
Get-BitLockerVolume | Where-Object { $_.ProtectionStatus -eq 'On' } |
Select-Object MountPoint, VolumeType, EncryptionPercentage, ProtectionStatus
确认哪些卷已启用且含恢复密钥保护器(通常 RecoveryPassword 类型存在即表示可导出)。
批量导出每个卷的恢复密钥到独立 .txt 文件
以下脚本以管理员身份运行,为每个启用 BitLocker 的卷生成带时间戳的恢复密钥文件(如 C_RecoveryKey_20260721.txt):
$Date = Get-Date -Format "yyyyMMdd"
Get-BitLockerVolume | Where-Object { $_.ProtectionStatus -eq 'On' } | ForEach-Object {
$MountPoint = $_.MountPoint.TrimEnd(':')
$KeyInfo = ($_ | Get-BitLockerKeyProtector | Where-Object {$_.KeyProtectorType -eq 'RecoveryPassword'})
if ($KeyInfo) {
$RecoveryKey = $KeyInfo.RecoveryPassword
$FileName = "$MountPoint`_RecoveryKey_$Date.txt"
$RecoveryKey | Out-File -FilePath $FileName -Encoding UTF8 -Force
Write-Host "✅ 已导出 $MountPoint 恢复密钥 → $FileName"
} else {
Write-Warning "⚠️ $MountPoint 无 RecoveryPassword 保护器,跳过导出"
}
}
⚠️ 注意:该操作仅导出当前已配置的恢复密钥,不会重新生成新密钥。若某卷未设置恢复密钥(例如只用了 TPM+PIN),需先用
Add-BitLockerKeyProtector补上。
补充:为无恢复密钥的卷批量添加并导出
如果发现某些卷缺失恢复密钥(如仅靠 TPM 解锁),可先添加:
Get-BitLockerVolume | Where-Object { $_.ProtectionStatus -eq 'On' -and
!($_ | Get-BitLockerKeyProtector | Where-Object {$_.KeyProtectorType -eq 'RecoveryPassword'}) } |
ForEach-Object {
$vol = $_
Add-BitLockerKeyProtector -MountPoint $vol.MountPoint -RecoveryPasswordProtector -WarningAction SilentlyContinue
Write-Host "? 已为 $($vol.MountPoint) 添加恢复密码保护器"
}
之后再运行上面的导出脚本即可。
其他实用命令
-
查看某卷所有密钥保护器详情:
Get-BitLockerVolume -MountPoint "C:" | Get-BitLockerKeyProtector
-
导出恢复密钥到 Active Directory(域环境):
Backup-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId <id></id>
(ID 可从
Get-BitLockerKeyProtector输出中获取) -
导出全部信息为 CSV(含卷、密钥 ID、类型、状态):
Get-BitLockerVolume | ForEach-Object { $vol = $_ $protectors = $_ | Get-BitLockerKeyProtector $protectors | Select-Object @{n='MountPoint';e={$vol.MountPoint}}, KeyProtectorType, RecoveryPassword, KeyProtectorId } | Export-Csv .\BitLocker_Keys_Report.csv -NoTypeInformation
不复杂但容易忽略:恢复密钥必须提前导出并离线保管——一旦系统崩溃或 TPM 清除,没密钥就等于永久丢数据。











