使用公钥加密并Base64编码密码的PowerShell实现问题
解决PowerShell中Deeper Network Connect设备登录的RSA加密问题
在编写PowerShell脚本自动登录Deeper Network Connect设备并获取数据时,若通过调用OpenSSL加密密码并提交API请求,会收到decryptionError: Failed to decrypt password错误,而此前的Bash版本可正常运行。以下是无外部依赖的纯PowerShell解决方案:
$IPAddress = "192.168.11.199" $publicKeyFile = "D:\certs\keys\deeper\deeper.pem" $Password = 'password' # 后续会移除硬编码 $bytes = [System.Text.Encoding]::UTF8.GetBytes($Password) $rsa = New-Object System.Security.Cryptography.RSACryptoServiceProvider $rsa.ImportFromPem([string](Get-Content $publicKeyFile)) # 使用设备要求的OAEP SHA1填充模式加密 $encryptedData = $rsa.Encrypt($bytes, [System.Security.Cryptography.RSAEncryptionPadding]::OaepSHA1) $encryptedPassword = [System.Convert]::ToBase64String($encryptedData) # 调用登录API获取Token $Token = ((Invoke-WebRequest -UseBasicParsing -Uri "http://$($IPAddress)/api/admin/login" ` -Method POST ` -ContentType "application/json; charset=utf-8" ` -Body "{\"username\":\"admin\",\"password\":\"$encryptedPassword\"}" | Select-Object -ExpandProperty Content) | ConvertFrom-Json | Select-Object token).token $Token
关键说明
- 问题根源:PowerShell调用OpenSSL时的加密参数(如填充模式)与设备后端解密逻辑不匹配,而纯PowerShell方案直接使用
.NET的RSACryptoServiceProvider,严格匹配设备要求的OAEP SHA1填充模式(对应前端authUtils.js的加密逻辑)。 - 无外部依赖:全程使用PowerShell内置的
.NET类库,无需额外安装OpenSSL或其他工具。
内容的提问来源于stack exchange,提问作者user5062856
相关产品推荐
相关产品推荐

