You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server 2019中GPG脚本--secret-keyring参数替代方案求助

问题描述

在Windows Server 2016上通过任务计划程序触发运行的PowerShell脚本可正常完成GPG签名操作,但部署到Windows Server 2019时,执行提示--secret-keyring参数已过时并被忽略,日志显示未找到默认密钥,无法完成文件签名。尝试指向private-keys-v1.d目录未解决问题,原脚本代码如下:

foreach ($item in $items)
{
    #if the item name contains date, then process it.
    if ($item.FullName -like "*.txt")
    {
        #Write-Host $item.FullName
        set-alias gpg2 "C:\Program Files (x86)\GnuPG\bin\gpg.exe"                    
        gpg2 --default-key "test@uat.co.uk" --pinentry-mode loopback --batch --yes --passphrase-file="D:\AutomatedJobs\abc\def\Cred\PGP-Creds.txt" --keyring "C:\Users\svc.xxx\AppData\Roaming\gnupg\pubring.kbx" --secret-keyring "C:\Users\svc.xxx\AppData\Roaming\gnupg\pubring.kbx" --log-file "D:\AutomatedJobs\abc\def\Logs\Sign-$(get-date -f yyyyMMdd).log" --verbose --force-mdc --trust-model always --output "$item.asc" --sign $item.FullName  
        Remove-Item $item.FullName
    }
}
解决方案
  • 移除过时的--secret-keyring参数:GnuPG 2.1及以上版本已废弃单独的私钥环文件,私钥默认存储在GnuPG主目录下的private-keys-v1.d文件夹中,无需再指定该参数。
  • 统一指定GnuPG主目录(可选):如果密钥不在默认路径,不需要单独指定公钥环,改用--homedir参数指定完整的GnuPG主目录路径,让gpg自动加载公钥和私钥,例如:--homedir "C:\Users\svc.xxx\AppData\Roaming\gnupg"
  • 确认服务账户的密钥存在:任务计划程序运行时使用的是svc.xxx账户上下文,需确保该账户的GnuPG目录下已导入目标私钥。可在PowerShell中以该账户身份执行gpg2 --list-secret-keys test@uat.co.uk,验证密钥是否存在。
  • 修改后的脚本示例:
foreach ($item in $items)
{
    if ($item.FullName -like "*.txt")
    {
        set-alias gpg2 "C:\Program Files (x86)\GnuPG\bin\gpg.exe"                    
        gpg2 --default-key "test@uat.co.uk" --pinentry-mode loopback --batch --yes `
            --passphrase-file="D:\AutomatedJobs\abc\def\Cred\PGP-Creds.txt" `
            --homedir "C:\Users\svc.xxx\AppData\Roaming\gnupg" `
            --log-file "D:\AutomatedJobs\abc\def\Logs\Sign-$(get-date -f yyyyMMdd).log" `
            --verbose --force-mdc --trust-model always --output "$($item.FullName).asc" --sign $item.FullName  
        Remove-Item $item.FullName
    }
}

注:修正了输出路径的小问题,原脚本中"$item.asc"会输出类似FileInfo.asc的错误文件名,改为"$($item.FullName).asc"才能生成正确的.asc文件。

内容的提问来源于stack exchange,提问作者Shaw Wright

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 19:45:04