离线VPN环境下Git连接Azure DevOps Server无法使用Windows凭据求助
如何让Windows凭据在本地Azure DevOps Server仓库生效,无需每次使用PAT?
问题描述
直接执行git pull会报错:
fatal: Authentication failed for 'https://xxxap01/xxxApps/xxxPreview/_git/xxxPreview/
目前只能通过带认证头的命令拉取代码:git -c http.extraHeader="Authorization: Basic $b64pat" pull,希望配置Windows凭据管理器让普通git pull命令正常生效。
环境信息
- Git仓库部署在本地Azure DevOps Server 2020(合规要求),需通过VPN连接,连接后无法访问互联网
- 可通过本地浏览器访问
https://xxxap01/xxxApps,但会提示输入域账号mysecuredomainaccount@securedomain.dk和密码(自签名SSL证书已添加到用户"受信任的根证书颁发机构"存储) - DevOps Server托管在Windows Server 2019上,IIS未安装Basic Auth认证
已执行操作
- 在Windows"凭据管理器"中添加通用凭据,目标为
git:https://xxxap01/xxxApps,填入对应账号和密码 - 执行Git配置命令:
git credential-manager unconfiguregit config --global credential.helper wincred
- 执行
git credential-manager azure-repos list https://xxxap01/xxxApps,返回结果:..> (global) -> mysecuredomainaccount@securedomain.dk
诊断日志错误信息
ICredentialStore instance is of type: CredentialStore Writing test credential... OK Reading test credential... OK Deleting test credential... OK ------------ Diagnostic: Microsoft authentication (AAD/MSA) Skipped: False Success: True Exception: None Log: Broker not supported. Flow type is: Auto Gathering MSAL token cache data... OK CacheDirectory: C:\Users\jrt\AppData\Local\.IdentityService CacheFileName: msal.cache CacheFilePath: C:\Users\jrt\AppData\Local\.IdentityService\msal.cache Creating cache helper... OK Verifying MSAL token cache persistence... OK ------------ Diagnostic: GitHub API Skipped: False Success: False Exception: System.Net.Http.HttpRequestException: An error occurred while sending the request. ---> System.Net.WebException: The remote name could not be resolved: 'api.github.com' at System.Net.HttpWebRequest.EndGetResponse(IAsyncResult asyncResult) at System.Net.Http.HttpClientHandler.GetResponseCallback(IAsyncResult ar) --- End of inner exception stack trace --- at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task) at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task) at System.Runtime.CompilerServices.TaskAwaiter`1.GetResult() at GitHub.GitHubRestApi.<GetMetaInfoAsync>d__5.MoveNext() --- End of stack trace from previous location where exception was thrown --- at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task) at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task) at System.Runtime.CompilerServices.TaskAwaiter`1.GetResult() at GitHub.Diagnostics.GitHubApiDiagnostic.<RunInternalAsync>d__2.MoveNext() --- End of stack trace from previous location where exception was thrown --- at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task) at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task) at System.Runtime.CompilerServices.TaskAwaiter`1.GetResult() at GitCredentialManager.Diagnostics.Diagnostic.<RunAsync>d__5.MoveNext() Log: Using 'https://github.com/' as API target. Querying '/meta' endpoint...
问题分析
- GitHub API诊断失败是因为VPN连接后无法访问互联网,干扰了Git Credential Manager (GCM)的自动检测逻辑,导致它无法正确识别本地Azure DevOps Server的认证方式
- IIS未安装Basic Auth但浏览器能通过域账号登录,说明DevOps Server使用NTLM/Kerberos集成认证,旧版
wincred凭据助手无法适配该场景
解决步骤
1. 强制GCM识别本地Azure DevOps Server
执行全局配置命令,明确指定目标服务器的认证提供者:
git config --global credential.azureRepos.useHttpPath true git config --global credential.https://xxxap01/xxxApps.provider azure-devops
2. 切换到适配集成认证的凭据助手
替换旧版wincred为manager-core,并启用Windows集成认证:
git credential-manager unconfigure git config --global credential.helper manager-core git config --global credential.https://xxxap01/xxxApps.integrated true
3. 清理旧凭据并重新认证
- 打开Windows凭据管理器,删除所有与
xxxap01相关的凭据 - 执行
git pull,在弹出的Windows认证窗口输入域账号和密码,勾选"记住我的凭据"
4. 可选:跳过Git SSL额外验证(仅信任本地环境时使用)
若Git仍因自签名证书报错,执行:
git config --global http.sslVerify false
5. 验证配置
执行以下命令确认配置正确:
git config --global --list | grep credential git credential-manager azure-repos list https://xxxap01/xxxApps
内容的提问来源于stack exchange,提问作者Jørgen Thyme
相关产品推荐
相关产品推荐

