为何我的PowerShell Secrets Cmdlet现在抛出异常?
PowerShell 机密库 Cmdlet 报错:Padding is invalid and cannot be removed.
运行任何机密库相关Cmdlet时都会触发如下错误:
Get-SecretInfo: Exception calling "GetInstance" with "0" argument(s):
"Padding is invalid and cannot be removed."
示例执行的命令:
get-secret -Vault Secrets -Name SecretName -AsPlainText
对应的错误输出:
Get-Secret: Exception calling "GetInstance" with "0" argument(s):
"Padding is invalid and cannot be removed." Get-Secret: Exception
calling "GetInstance" with "0" argument(s): "Padding is invalid and
cannot be removed." Get-Secret: The secret SecretName was not found.
当前使用的是最新版PowerShell,求解决办法或替代方案。
修复方法
重置本地机密库加密密钥
这个错误大多是机密库的加密状态损坏导致的,重置密钥可以解决:
Reset-SecretVault -Name Secrets -Force
⚠️ 注意:执行后该Vault内所有现有机密会被清除,操作前务必确认已备份。
重新注册机密库
先注销现有Vault,再重新注册初始化:
Unregister-SecretVault -Name Secrets Register-SecretVault -Name Secrets -ModuleName Microsoft.PowerShell.SecretStore -DefaultVault
重新注册时会引导你设置新的加密密码和存储配置。
更新SecretStore模块
即便PowerShell是最新版,对应的SecretStore模块可能不是最新,执行更新:
Update-Module -Name Microsoft.PowerShell.SecretStore -Force
替代方案
如果以上方法都无效,可以换用其他机密管理方式:
- Windows凭据管理器:安装
CredentialManager模块后,用Get-StoredCredential/Set-StoredCredentialCmdlet管理凭据。 - 环境变量存储:对非高度敏感的信息,可临时存入环境变量,通过
$env:SecretName调用。 - 本地加密文件:用
ConvertTo-SecureString和ConvertFrom-SecureString配合自定义密钥加密本地文件,手动管理机密存储。
内容的提问来源于stack exchange,提问作者whytheq
相关产品推荐
相关产品推荐

