如何通过PowerShell批量查询主机支持的TLS版本?
批量查询Windows主机支持的TLS版本方法
方法一:远程TLS握手测试(无需额外组件)
这种方法通过向目标主机发起不同TLS版本的连接请求,根据连接是否成功判断该主机是否支持对应版本,完全不需要在远程主机安装任何组件,适合批量检测。
示例脚本
# 定义要检测的主机列表 $hostList = @("DC01", "PC01", "Server01") # 定义要检测的TLS版本 $tlsVersions = @( @{Name="TLS 1.0"; Protocol=[System.Net.SecurityProtocolType]::Tls}, @{Name="TLS 1.1"; Protocol=[System.Net.SecurityProtocolType]::Tls11}, @{Name="TLS 1.2"; Protocol=[System.Net.SecurityProtocolType]::Tls12}, @{Name="TLS 1.3"; Protocol=[System.Net.SecurityProtocolType]::Tls13} ) # 循环检测每个主机 foreach ($computer in $hostList) { Write-Host "`n=== 检测主机: $computer ===" $result = @{ComputerName = $computer} foreach ($tls in $tlsVersions) { try { # 创建TLS连接(这里用LDAP端口389,贴合域认证兼容性检测,也可替换为443、636等SSL端口) $tcpClient = New-Object System.Net.Sockets.TcpClient($computer, 389) $sslStream = New-Object System.Net.Security.SslStream($tcpClient.GetStream(), $false) $sslStream.AuthenticateAsClient($computer, $null, $tls.Protocol, $false) $result[$tls.Name] = "支持" $sslStream.Close() $tcpClient.Close() } catch { $result[$tls.Name] = "不支持/已禁用" } } # 输出结果 [PSCustomObject]$result | Format-Table -AutoSize }
说明:
- 可根据实际场景修改连接端口,比如域控的LDAPS端口636,确保目标端口开启SSL/TLS服务
- 对不支持TLS1.3的系统(如Windows 7),发起TLS1.3连接会直接报错,标记为不支持
方法二:注册表查询+默认规则判断
Windows系统中,未被手动修改过的TLS协议不会在HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols下创建对应键,此时遵循系统默认启用规则。以下脚本结合注册表实际配置和默认规则给出准确结果:
示例脚本
# 定义要检测的主机列表 $hostList = @("DC01", "PC01", "Server01") # 定义TLS协议路径和默认规则 $protocolPaths = @( @{Name="TLS 1.0"; Path="TLS 1.0\Client"; DefaultEnabled=$true}, @{Name="TLS 1.1"; Path="TLS 1.1\Client"; DefaultEnabled=$true}, @{Name="TLS 1.2"; Path="TLS 1.2\Client"; DefaultEnabled=$true}, @{Name="TLS 1.3"; Path="TLS 1.3\Client"; DefaultEnabled=$false} # Windows 10 1903+/Server 2019+默认启用,后续根据系统版本调整 ) foreach ($computer in $hostList) { Write-Host "`n=== 检测主机: $computer ===" $result = @{ComputerName = $computer} # 获取系统版本,调整TLS1.3默认值 try { $osVersion = Invoke-Command -ComputerName $computer -ScriptBlock { (Get-CimInstance Win32_OperatingSystem).Version } -ErrorAction Stop # Windows 10 1903+版本号 >= 10.0.18362,Server 2019+ >= 10.0.17763 if ($osVersion -ge "10.0.17763") { $protocolPaths | Where-Object {$_.Name -eq "TLS 1.3"} | ForEach-Object {$_.DefaultEnabled = $true} } } catch { Write-Warning "无法获取$computer的系统版本,TLS1.3默认按不支持处理" } foreach ($proto in $protocolPaths) { try { $regPath = "HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\$($proto.Path)" # 读取远程注册表 $regProps = Get-ItemProperty -Path "\\$computer\$regPath" -ErrorAction Stop # 判断启用状态:DisabledByDefault=0 且 Enabled=1 表示启用 if ($regProps.DisabledByDefault -eq 0 -and $regProps.Enabled -eq 1) { $result[$proto.Name] = "已启用(手动配置)" } else { $result[$proto.Name] = "已禁用(手动配置)" } } catch [System.Management.Automation.ItemNotFoundException] { # 注册表项不存在,使用默认规则 $result[$proto.Name] = if ($proto.DefaultEnabled) { "已启用(默认)" } else { "不支持/已禁用(默认)" } } catch { $result[$proto.Name] = "检测失败:$($_.Exception.Message)" } } [PSCustomObject]$result | Format-Table -AutoSize }
说明:
- 需要目标主机开启远程注册表服务(Remote Registry),且当前用户有读取远程注册表的权限
- 脚本会根据系统版本自动调整TLS1.3的默认启用状态,结果更准确
批量检测注意事项
- 优先使用方法一,无需依赖远程服务,结果更贴合实际连接情况(注册表配置可能和实际运行状态有差异)
- 批量检测时建议加入错误处理,跳过离线或无权限的主机
- 如果要检测服务器端的TLS支持(比如域控自身的TLS版本),可将脚本中的Client路径改为Server路径
内容的提问来源于stack exchange,提问作者aristosv
相关产品推荐
相关产品推荐

