Azure管道中修改Function App TLS密码套件致ARM模板部署失败
我在Azure创建新站点时尝试更新配置,目标是将最低TLS密码套件从最不安全的TLS_RSA_WITH_AES_128_CBC_SHA修改为TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256。使用旧套件时部署正常,但修改后Azure管道执行失败,本地PowerShell操作可成功。
已尝试的Azure管道任务配置
- 先后使用AzurePowerShell@4和AzurePowerShell@5任务,配置示例如下:
- task: AzurePowerShell@4 inputs: azureSubscription: xx ScriptType: 'FilePath' ScriptPath: xx ScriptArguments: xx azurePowerShellVersion: 'LatestVersion'
环境信息
- 本地环境:PowerShell版本
5.1.19041.4412 - Azure管道代理:采用windows-latest镜像,PowerShell版本
5.1.20348.2400
更新Function App时的错误日志
The underlying connection was closed: An unexpected error occurred on a send.
Retrying after 10 seconds
The underlying connection was closed: An unexpected error occurred on a send.
Retrying after 10 seconds
The underlying connection was closed: An unexpected error occurred on a send.
##[error]The function call failed 3 times. Failing step
##[error]PowerShell exited with code '1'.
ARM模板中触发失败的配置段
"scmIpSecurityRestrictionsUseMain": false, "http20Enabled": false, "minTlsVersion": "1.2", "minTlsCipherSuite": "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256", "ftpsState": "AllAllowed", "reservedInstanceCount": 0
仅将minTlsCipherSuite从TLS_RSA_WITH_AES_128_CBC_SHA修改为上述值时触发错误,同时调试信息显示:
##[debug]Error record:
##[debug]PackageManagement\Save-Package : No match was found for the specified search criteria and module name 'Az'. Try Get-PSRepository to see all available registered module repositories.
##[debug]At C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\2.2.5\PSModule.psm1:11794 char:21
##[debug]+ $null = PackageManagement\Save-Package @PSBoundParameters
##[debug]+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
##[debug] + CategoryInfo : ObjectNotFound: (Microsoft.Power...ets.SavePackage:SavePackage) [Save-Package], Exception
##[debug] + FullyQualifiedErrorId : NoMatchFoundForCriteria,Microsoft.PowerShell.PackageManagement.Cmdlets.SavePackage
##[debug]
##[debug]Script stack trace:
##[debug]at Save-Module<Process>, C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\2.2.5\PSModule.psm1: line 11794
##[debug]at <ScriptBlock>, D:\a_tasks\AzurePowerShell_72a1931b\4.240.6\TryMakingModuleAvailable.ps1: line 75
##[debug]at <ScriptBlock>, D:\a_tasks\AzurePowerShell_72a1931\4.240.6\azurepowershell.ps1: line 53
##[debug]at <ScriptBlock>, <No file>: line 1
##[debug]at <ScriptBlock>, <No file>: line 22
##[debug]at <ScriptBlock>, <No file>: line 18
##[debug]at <ScriptBlock>, <No file>: line 1
##[debug]Exception:
##[debug]System.Exception: No match was found for the specified search criteria and module name 'Az'. Try Get-PSRepository to see all available registered module repositories.
内容的提问来源于stack exchange,提问作者DangerousDave

