You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server 2016中StoreBroker认证失败问题求助

解决Windows Server 2016上StoreBroker连接失败问题

针对你遇到的在Windows Server 2016上执行StoreBroker脚本时出现的「底层连接关闭」错误,以下是针对性的解决思路:

1. 强制启用系统级TLS 1.2支持

虽然脚本中设置了[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12,但Windows Server 2016的.NET Framework默认可能未强制启用强加密套件。需添加注册表项确保系统层面支持TLS 1.2:

# 启用.NET Framework 4.x的强加密设置(32位和64位)
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319' -Name 'SchUseStrongCrypto' -Value 1 -Type DWord
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319' -Name 'SchUseStrongCrypto' -Value 1 -Type DWord

# 启用系统TLS 1.2客户端设置
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client' -Name 'Enabled' -Value 1 -Type DWord
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client' -Name 'DisabledByDefault' -Value 0 -Type DWord

执行后重启服务器,使注册表设置生效。

2. 更新StoreBroker模块至最新版本

你当前使用的是1.21.2版本,该版本可能存在与Windows Server 2016的兼容性问题。更新到最新版本:

Update-Module -Name StoreBroker -Force

更新后重新执行脚本,验证问题是否解决。

3. 检查出站网络限制

  • 确认Windows Server 2016的防火墙/安全组允许访问Windows商店 ingestion API的相关域名(如manage.devcenter.microsoft.com、login.microsoftonline.com)。
  • 如果服务器通过代理上网,需在脚本中添加代理配置:
    # 替换为你的代理地址和端口
    $proxyAddress = "http://your-proxy-server:port"
    [System.Net.WebRequest]::DefaultWebProxy = New-Object System.Net.WebProxy($proxyAddress)
    [System.Net.WebRequest]::DefaultWebProxy.Credentials = [System.Net.CredentialCache]::DefaultCredentials
    

4. 升级.NET Framework版本

Windows Server 2016默认的.NET Framework版本(4.6.x)对TLS 1.2的支持不够完善,建议升级至.NET Framework 4.7.2或更高版本,确保StoreBroker模块能正常建立TLS连接。


内容的提问来源于stack exchange,提问作者Volkhard Vogeler

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 04:42:16