You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linux通过SSH调用Windows 2022 PowerCLI脚本连接vCenter失败问题

解决Linux SSH调用Windows Server 2022 PowerCLI脚本无法连接vCenter的问题

核心问题分析

报错的CryptographicException本质是:Windows Server 2022默认加强了DPAPI(数据保护API)的权限控制,非交互式会话(SSH远程调用属于此类)无法读取用户本地创建的DPAPI加密凭据文件(Cred.xml是通过New-VICredentialStoreItem用当前用户DPAPI加密的),而用户通过VMware控制台登录时属于交互式会话,可正常访问DPAPI存储。

可行解决方案

方案1:替换DPAPI加密凭据为AES密钥加密(推荐)

绕过DPAPI的会话限制,改用独立AES密钥加密存储vCenter凭据:

  1. 生成并保存AES密钥(仅执行一次):
    # 生成256位AES密钥
    $AESKey = New-Object Byte[] 32
    [System.Security.Cryptography.RNGCryptoServiceProvider]::Create().GetBytes($AESKey)
    # 保存密钥到本地文件,限制权限仅USER和管理员可访问
    $AESKey | Out-File C:\Scripts\AESKey.txt
    icacls C:\Scripts\AESKey.txt /inheritance:r /grant USER:F /grant Administrators:F
    
  2. 重新加密保存vCenter凭据:
    $vCenterUser = "你的vCenter用户名"
    $vCenterPass = ConvertTo-SecureString "你的vCenter密码" -AsPlainText -Force
    $credential = New-Object System.Management.Automation.PSCredential ($vCenterUser, $vCenterPass)
    # 用AES密钥加密导出凭据
    $credential | Export-Clixml -Path C:\Scripts\VCred.xml -EncryptionKey (Get-Content C:\Scripts\AESKey.txt)
    
  3. 修改PowerShell脚本的凭据读取逻辑:
    # 读取AES密钥和加密凭据
    $AESKey = Get-Content C:\Scripts\AESKey.txt
    $Credentials = Import-Clixml -Path C:\Scripts\VCred.xml -EncryptionKey $AESKey
    # 连接vCenter
    Connect-VIServer VICENTER -Credential $Credentials
    

方案2:调整Windows Server 2022的DPAPI非交互式访问策略

修改系统策略,允许非交互式会话访问用户DPAPI存储:

  1. 本地组策略配置:
    • 打开gpedit.msc,导航到计算机配置→管理模板→系统→凭据分配
    • 启用允许分配默认凭据仅用于NTLM服务器身份验证,添加目标:TERMSRV/*、wsman/*
    • 启用允许分配保存的凭据仅用于NTLM服务器身份验证,添加相同目标
  2. 注册表补充配置:
    • 打开注册表编辑器,导航到HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
    • 添加REG_DWORD值AllowDefaultCredentials,设为1
    • 添加REG_DWORD值AllowSavedCredentials,设为1
    • 创建子项DefaultCredentialsAllowlist,在其中添加字符串值TERMSRV/*和wsman/*
    • 创建子项SavedCredentialsAllowlist,在其中添加相同字符串值
  3. 重启Windows Server 2022使配置生效

方案3:临时用任务计划在交互式上下文执行(应急用)

通过任务计划让脚本在用户的交互式会话上下文运行,绕过非交互式限制(安全性较低,不推荐长期使用):

# Linux端SSH调用命令示例
ssh USER@WINDOWS_HOST 'schtasks /create /tn "VMMigrationTask" /tr "powershell.exe -File C:\Scripts\Mover_VM_entre_sitios.ps1 -TargetSite 目标站点 -VM 待迁移VM名" /sc once /st (Get-Date).AddMinutes(1).ToString("HH:mm") /ru USER /rp "USER密码" /f && schtasks /run /tn "VMMigrationTask"'

验证步骤

  1. 确保USER未登录Windows Server 2022
  2. 从Linux执行SSH调用命令
  3. 检查脚本是否成功连接vCenter,无CryptographicException报错

内容的提问来源于stack exchange,提问作者LucasDT

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 11:07:41