You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell批量查询主机支持的TLS版本?

批量查询Windows主机支持的TLS版本方法

方法一:远程TLS握手测试(无需额外组件)

这种方法通过向目标主机发起不同TLS版本的连接请求,根据连接是否成功判断该主机是否支持对应版本,完全不需要在远程主机安装任何组件,适合批量检测。

示例脚本

# 定义要检测的主机列表
$hostList = @("DC01", "PC01", "Server01")
# 定义要检测的TLS版本
$tlsVersions = @(
    @{Name="TLS 1.0"; Protocol=[System.Net.SecurityProtocolType]::Tls},
    @{Name="TLS 1.1"; Protocol=[System.Net.SecurityProtocolType]::Tls11},
    @{Name="TLS 1.2"; Protocol=[System.Net.SecurityProtocolType]::Tls12},
    @{Name="TLS 1.3"; Protocol=[System.Net.SecurityProtocolType]::Tls13}
)

# 循环检测每个主机
foreach ($computer in $hostList) {
    Write-Host "`n=== 检测主机: $computer ==="
    $result = @{ComputerName = $computer}
    
    foreach ($tls in $tlsVersions) {
        try {
            # 创建TLS连接(这里用LDAP端口389,贴合域认证兼容性检测,也可替换为443、636等SSL端口)
            $tcpClient = New-Object System.Net.Sockets.TcpClient($computer, 389)
            $sslStream = New-Object System.Net.Security.SslStream($tcpClient.GetStream(), $false)
            $sslStream.AuthenticateAsClient($computer, $null, $tls.Protocol, $false)
            
            $result[$tls.Name] = "支持"
            $sslStream.Close()
            $tcpClient.Close()
        }
        catch {
            $result[$tls.Name] = "不支持/已禁用"
        }
    }
    
    # 输出结果
    [PSCustomObject]$result | Format-Table -AutoSize
}

说明:

  • 可根据实际场景修改连接端口,比如域控的LDAPS端口636,确保目标端口开启SSL/TLS服务
  • 对不支持TLS1.3的系统(如Windows 7),发起TLS1.3连接会直接报错,标记为不支持

方法二:注册表查询+默认规则判断

Windows系统中,未被手动修改过的TLS协议不会在HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols下创建对应键,此时遵循系统默认启用规则。以下脚本结合注册表实际配置和默认规则给出准确结果:

示例脚本

# 定义要检测的主机列表
$hostList = @("DC01", "PC01", "Server01")
# 定义TLS协议路径和默认规则
$protocolPaths = @(
    @{Name="TLS 1.0"; Path="TLS 1.0\Client"; DefaultEnabled=$true},
    @{Name="TLS 1.1"; Path="TLS 1.1\Client"; DefaultEnabled=$true},
    @{Name="TLS 1.2"; Path="TLS 1.2\Client"; DefaultEnabled=$true},
    @{Name="TLS 1.3"; Path="TLS 1.3\Client"; DefaultEnabled=$false} # Windows 10 1903+/Server 2019+默认启用,后续根据系统版本调整
)

foreach ($computer in $hostList) {
    Write-Host "`n=== 检测主机: $computer ==="
    $result = @{ComputerName = $computer}
    
    # 获取系统版本,调整TLS1.3默认值
    try {
        $osVersion = Invoke-Command -ComputerName $computer -ScriptBlock { (Get-CimInstance Win32_OperatingSystem).Version } -ErrorAction Stop
        # Windows 10 1903+版本号 >= 10.0.18362,Server 2019+ >= 10.0.17763
        if ($osVersion -ge "10.0.17763") {
            $protocolPaths | Where-Object {$_.Name -eq "TLS 1.3"} | ForEach-Object {$_.DefaultEnabled = $true}
        }
    }
    catch {
        Write-Warning "无法获取$computer的系统版本,TLS1.3默认按不支持处理"
    }

    foreach ($proto in $protocolPaths) {
        try {
            $regPath = "HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\$($proto.Path)"
            # 读取远程注册表
            $regProps = Get-ItemProperty -Path "\\$computer\$regPath" -ErrorAction Stop
            
            # 判断启用状态:DisabledByDefault=0 且 Enabled=1 表示启用
            if ($regProps.DisabledByDefault -eq 0 -and $regProps.Enabled -eq 1) {
                $result[$proto.Name] = "已启用(手动配置)"
            } else {
                $result[$proto.Name] = "已禁用(手动配置)"
            }
        }
        catch [System.Management.Automation.ItemNotFoundException] {
            # 注册表项不存在,使用默认规则
            $result[$proto.Name] = if ($proto.DefaultEnabled) { "已启用(默认)" } else { "不支持/已禁用(默认)" }
        }
        catch {
            $result[$proto.Name] = "检测失败:$($_.Exception.Message)"
        }
    }
    
    [PSCustomObject]$result | Format-Table -AutoSize
}

说明:

  • 需要目标主机开启远程注册表服务(Remote Registry),且当前用户有读取远程注册表的权限
  • 脚本会根据系统版本自动调整TLS1.3的默认启用状态,结果更准确

批量检测注意事项

  • 优先使用方法一,无需依赖远程服务,结果更贴合实际连接情况(注册表配置可能和实际运行状态有差异)
  • 批量检测时建议加入错误处理,跳过离线或无权限的主机
  • 如果要检测服务器端的TLS支持(比如域控自身的TLS版本),可将脚本中的Client路径改为Server路径

内容的提问来源于stack exchange,提问作者aristosv

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 09:00:56