执行PowerShell脚本调用Conjur接口时遇远程连接失败问题求助
排查Conjur凭据获取脚本的远程连接失败问题
执行的PowerShell脚本
# Create a dictionary to store headers $headers = New-Object "System.Collections.Generic.Dictionary[[String],[String]]" $headers.Add("Authorization", "Token token=") # Define the URL $url = "https://dap- follower.aws.corpads.local/secrets/conjurprod/variable/vault/LOB_User1/SRV_HrzCloudEng/SVC_AWSDS@corpads.local/password" # Perform an HTTP GET request $response = Invoke-RestMethod -Uri $url -Method GET -Headers $headers # Convert the response to JSON $response | ConvertTo-Json
执行错误信息
Invoke-RestMethod: Unable to connect to the remote server At line:3 char:13
- Sresponse Invoke-RestMethod https://dap-follower aws. corpads.local/...
+CategoryInfo: InvalidOperation: (System.Net.HttpWebRequest: HttpWebRequest) [Invoke-RestMethod], WebException + FullyQualifiedErrorId : WebCmdletWebResponseException, Microsoft. Power Shell.Commands. InvokeRestMethodCommand
排查步骤
- 修正URL格式:当前URL存在多余空格,
dap- follower应改为dap-follower,aws. corpads.local应改为aws.corpads.local,空格会导致地址解析失败,修正后的URL为:https://dap-follower.aws.corpads.local/secrets/conjurprod/variable/vault/LOB_User1/SRV_HrzCloudEng/SVC_AWSDS@corpads.local/password - 验证网络连通性:在PowerShell中执行
Test-Connection dap-follower.aws.corpads.local,确认DNS解析和服务器可达性;也可执行Invoke-WebRequest -Uri https://dap-follower.aws.corpads.local -UseBasicParsing测试基础HTTPS连接。 - 补全认证Token:当前
Authorization头的Token token=为空,Conjur需要有效认证Token才能访问,格式应为Token token="your-valid-conjur-token",需先完成Conjur身份认证流程获取合法Token。 - 处理SSL证书问题:若目标服务器使用自签名证书,PowerShell默认会拒绝连接,可临时添加
-SkipCertificateCheck参数测试(生产环境不推荐),或把证书导入本地信任存储。 - 检查代理配置:如果环境需要代理,需在脚本中添加
-Proxy参数指定代理地址,或确认PowerShell默认代理配置正确。
内容的提问来源于stack exchange,提问作者Karan Jeet
相关产品推荐
相关产品推荐

