SharePoint 2013与Oracle连接异常及Secure Store Service故障排查求助
核心症状梳理
- 部分Web部件无法从Oracle服务器获取数据
- 无法访问Secure Store Service,提示「抱歉,此站点未共享给您」
- ULS日志报错:EventID 8311(SSL策略错误)、EventID 7557(Secure Store Service代理不可访问),通信目标为本机32844端口
- 中央管理(Central Admin)站点仅支持HTTP访问,无法使用HTTPS
- 执行自定义PowerShell脚本更新密钥时,报错「cannot update the secure store master key. Exception calling 'Invoke' with '2' arguments」
一、修复Secure Store Service访问权限
- 确认账户权限:
- 打开中央管理 → 应用程序管理 → 管理服务应用程序
- 找到Secure Store Service应用程序,右键选择「管理」
- 检查「管理员」列表,确保你的账户在其中;若不在,添加后重启Secure Store Service服务
- 同时确认账户拥有中央管理站点的完全控制权限,以及SharePoint服务器本地管理员权限
二、解决SSL策略错误与32844端口问题
32844是SharePoint应用程序服务默认端口,报错与CA仅支持HTTP有关,需检查端点配置:
- 打开中央管理 → 应用程序管理 → 配置服务应用程序关联
- 确认Secure Store Service代理已关联到目标Web应用程序
- 进入系统设置 → 管理服务器上的服务,找到Secure Store Service并点击「属性」:
- 若环境未配置SSL,确保服务端点使用HTTP而非HTTPS
- 验证端口为32844,若端口异常,尝试重置服务端口
- 测试端口连通性:在SharePoint服务器执行命令:
确保端口可正常访问Test-NetConnection localhost -Port 32844
三、修正Secure Store密钥更新脚本
原脚本报错因GetPassPhraseHash方法参数格式错误,修正后脚本如下:
$sa = Get-SPServiceApplication 9ebf067e-2161-42b5-87ac-9c6f0a3eaf66; $proxy = Get-SPServiceApplicationProxy 4d13d637-d6e5-41d4-a7ea-0c9aef3d7769; $sp_secure_store_passpharse_new = "micro8845"; try{ $ass = $sa.GetType().Assembly $CryptoHelperType = $ass.GetType("Microsoft.Office.SecureStoreService.Server.CryptoHelper") # 修正:GetPassPhraseHash需传入密码+哈希算法两个参数 $GetPassPhraseHashMethod=$CryptoHelperType.GetMethod("GetPassPhraseHash", [type[]]@([string], [string])) $proxyType = $proxy.GetType(); $IsMasterSecretKeyPopulated = $proxyType.GetMethod("IsMasterSecretKeyPopulated",[Reflection.BindingFlags]"NonPublic,Instance") $SetChangeKeyPassphrase = $proxyType.GetMethod("SetChangeKeyPassphrase",[Reflection.BindingFlags]"NonPublic,Instance") $SetKey = $proxyType.GetMethod("SetKey",[Reflection.BindingFlags]"NonPublic,Instance", $null, [type[]]@([string]), $null) if(-not $IsMasterSecretKeyPopulated.Invoke($proxy,$null)){ $token = $sa.GetChangeMasterSecretKeyToken(); # 修正:传入SHA256作为哈希算法参数 $hash = $GetPassPhraseHashMethod.Invoke($null, @($sp_secure_store_passpharse_new, "SHA256")); $sa.ChangeMasterSecretKey($token, $hash ); $c=0; while(-not $IsMasterSecretKeyPopulated.Invoke($proxy,$null)){ $c++; if($c -ge 20){ Write-Error "The master key cannot be populated!"; break; } sleep 1; } } $SetChangeKeyPassphrase.Invoke($proxy, @($sp_secure_store_passpharse_new)); $SetKey.Invoke($proxy, @($sp_secure_store_passpharse_new)); }catch{ Write-Error "Cannot update the secure store master key.`n{0}" -f $_.Exception.Message; }
执行注意事项:
- 以SharePoint服务器场管理员身份运行SharePoint Management Shell
- 确保密码符合SharePoint密码复杂度要求
四、配置中央管理站点HTTPS访问
- 在IIS管理器中找到中央管理站点,右键→编辑绑定→添加HTTPS绑定,选择已有的SSL证书(或申请新证书)
- 执行PowerShell命令更新CA站点URL:
$caWebApp = Get-SPWebApplication -IncludeCentralAdministration | Where-Object { $_.IsAdministrationWebApplication -eq $true } $caWebApp.AlternateUrls.Add("https://你的CA域名:端口", [Microsoft.SharePoint.Administration.SPUrlZone]::Default) $caWebApp.Update() - 重启SharePoint Timer Service和IIS服务
五、验证Oracle数据连接
Secure Store恢复正常后,执行以下验证:
- 检查Secure Store中存储的Oracle凭据(用户名、密码、连接字符串)是否正确
- 确认Web部件关联的外部内容类型已绑定到正确的Secure Store目标应用
- 在SharePoint服务器使用
tnsping命令验证Oracle实例连通性
内容的提问来源于stack exchange,提问作者GeneralSiebenMC
相关产品推荐
相关产品推荐

