You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell调用API遇SSL/TLS信任错误及令牌加密方案求助

问题解决:SSL/TLS信任错误与Bearer令牌安全处理

一、解决SSL/TLS连接信任错误

出现Underlying connection was closed: Could not establish trust relationship for SSL/TLS secure channel错误,核心原因是目标API服务器的SSL证书未被本地系统信任,常见于自签证书或证书链不完整的场景。以下是两种解决方案:

1. 临时跳过证书验证(仅测试环境使用)

在调用Invoke-RestMethod前添加以下代码,强制跳过证书信任检查:

# 临时禁用证书验证
Add-Type @"
using System.Net;
using System.Security.Cryptography.X509Certificates;
public class TrustAllCertsPolicy : ICertificatePolicy {
    public bool CheckValidationResult(
        ServicePoint srvPoint, X509Certificate certificate,
        WebRequest request, int certificateProblem) {
        return true;
    }
}
"@
[System.Net.ServicePointManager]::CertificatePolicy = New-Object TrustAllCertsPolicy

注意:此方法会绕过所有SSL证书验证,存在安全风险,禁止在生产环境使用。

2. 导入信任证书(生产环境推荐)

将目标API服务器的根CA证书导入到本地计算机的「受信任的根证书颁发机构」存储中:

  • 打开目标API地址(https://example.xxxx),在浏览器中导出证书的根CA证书
  • 运行certlm.msc打开本地证书管理器
  • 导航到「受信任的根证书颁发机构」→「证书」,右键选择「所有任务」→「导入」,按照向导完成证书导入

额外代码修正:变量拼写错误

你的代码中存在变量名不一致问题:定义的请求头变量是$header,但$params中引用的是$headers,这会导致请求头未正确传递,需修正为统一变量名:

$headers = @{
   'Accept' = 'application/json'
   'Content-Type' = 'application/json'
   'Authorization' = 'Bearer XXXXXXXXXXXXXXXXXXX'
}

二、安全处理Bearer令牌

直接在代码中明文写令牌存在泄露风险,建议将令牌转换为安全字符串存储和使用:

1. 将明文令牌转换为安全字符串

# 将明文令牌转为安全字符串
$secureToken = ConvertTo-SecureString "你的Bearer令牌明文" -AsPlainText -Force

2. 持久化存储安全字符串(可选)

如果需要长期使用,可将安全字符串保存到本地文件:

# 保存到文件
$secureToken | ConvertFrom-SecureString | Out-File "C:\safe\path\to\secure_token.txt"

3. 读取安全字符串并生成Authorization头

# 从文件读取安全字符串
$savedSecureToken = Get-Content "C:\safe\path\to\secure_token.txt" | ConvertTo-SecureString

# 将安全字符串转换为明文令牌
$credential = New-Object System.Management.Automation.PSCredential ("dummy", $savedSecureToken)
$token = $credential.GetNetworkCredential().Password

# 构造请求头
$headers = @{
   'Accept' = 'application/json'
   'Content-Type' = 'application/json'
   'Authorization' = "Bearer $token"
}

最终修正后的完整代码

# 可选:测试环境临时跳过证书验证(生产环境注释此行及以下证书信任代码)
Add-Type @"
using System.Net;
using System.Security.Cryptography.X509Certificates;
public class TrustAllCertsPolicy : ICertificatePolicy {
    public bool CheckValidationResult(
        ServicePoint srvPoint, X509Certificate certificate,
        WebRequest request, int certificateProblem) {
        return true;
    }
}
"@
[System.Net.ServicePointManager]::CertificatePolicy = New-Object TrustAllCertsPolicy

# 读取安全令牌并构造请求头
$savedSecureToken = Get-Content "C:\safe\path\to\secure_token.txt" | ConvertTo-SecureString
$credential = New-Object System.Management.Automation.PSCredential ("dummy", $savedSecureToken)
$token = $credential.GetNetworkCredential().Password

$headers = @{
   'Accept' = 'application/json'
   'Content-Type' = 'application/json'
   'Authorization' = "Bearer $token"
}

$examdetails = @{"extra_vars" = @{"input" = "passed candidate name"}}

$params = @{
 'Method' = 'Post'
 'Uri' = 'https://example.xxxx/api/45213/launch'
 'Headers' = $headers
 'Body' = (ConvertTo-Json $examdetails)
}

$submissionofcandidate = Invoke-RestMethod @params

内容的提问来源于stack exchange,提问作者sgp031

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 19:22:56