You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SharePoint 2013与Oracle连接异常及Secure Store Service故障排查求助

SharePoint 2013本地环境故障排查与修复方案

核心症状梳理

  • 部分Web部件无法从Oracle服务器获取数据
  • 无法访问Secure Store Service,提示「抱歉,此站点未共享给您」
  • ULS日志报错:EventID 8311(SSL策略错误)、EventID 7557(Secure Store Service代理不可访问),通信目标为本机32844端口
  • 中央管理(Central Admin)站点仅支持HTTP访问,无法使用HTTPS
  • 执行自定义PowerShell脚本更新密钥时,报错「cannot update the secure store master key. Exception calling 'Invoke' with '2' arguments」

一、修复Secure Store Service访问权限

  1. 确认账户权限:
    • 打开中央管理 → 应用程序管理 → 管理服务应用程序
    • 找到Secure Store Service应用程序,右键选择「管理」
    • 检查「管理员」列表,确保你的账户在其中;若不在,添加后重启Secure Store Service服务
    • 同时确认账户拥有中央管理站点的完全控制权限,以及SharePoint服务器本地管理员权限

二、解决SSL策略错误与32844端口问题

32844是SharePoint应用程序服务默认端口,报错与CA仅支持HTTP有关,需检查端点配置:

  1. 打开中央管理 → 应用程序管理 → 配置服务应用程序关联
    • 确认Secure Store Service代理已关联到目标Web应用程序
  2. 进入系统设置 → 管理服务器上的服务,找到Secure Store Service并点击「属性」:
    • 若环境未配置SSL,确保服务端点使用HTTP而非HTTPS
    • 验证端口为32844,若端口异常,尝试重置服务端口
  3. 测试端口连通性:在SharePoint服务器执行命令:
    Test-NetConnection localhost -Port 32844
    
    确保端口可正常访问

三、修正Secure Store密钥更新脚本

原脚本报错因GetPassPhraseHash方法参数格式错误,修正后脚本如下:

$sa = Get-SPServiceApplication 9ebf067e-2161-42b5-87ac-9c6f0a3eaf66;
$proxy = Get-SPServiceApplicationProxy 4d13d637-d6e5-41d4-a7ea-0c9aef3d7769;
$sp_secure_store_passpharse_new = "micro8845";
try{
    $ass = $sa.GetType().Assembly
    $CryptoHelperType = $ass.GetType("Microsoft.Office.SecureStoreService.Server.CryptoHelper")
    # 修正:GetPassPhraseHash需传入密码+哈希算法两个参数
    $GetPassPhraseHashMethod=$CryptoHelperType.GetMethod("GetPassPhraseHash", [type[]]@([string], [string]))

    $proxyType = $proxy.GetType();
    $IsMasterSecretKeyPopulated = $proxyType.GetMethod("IsMasterSecretKeyPopulated",[Reflection.BindingFlags]"NonPublic,Instance")
    $SetChangeKeyPassphrase = $proxyType.GetMethod("SetChangeKeyPassphrase",[Reflection.BindingFlags]"NonPublic,Instance")
    $SetKey = $proxyType.GetMethod("SetKey",[Reflection.BindingFlags]"NonPublic,Instance", $null, [type[]]@([string]), $null)

    if(-not $IsMasterSecretKeyPopulated.Invoke($proxy,$null)){
        $token = $sa.GetChangeMasterSecretKeyToken();
        # 修正:传入SHA256作为哈希算法参数
        $hash = $GetPassPhraseHashMethod.Invoke($null, @($sp_secure_store_passpharse_new, "SHA256"));
        $sa.ChangeMasterSecretKey($token, $hash );

        $c=0;
        while(-not $IsMasterSecretKeyPopulated.Invoke($proxy,$null)){
            $c++;
            if($c -ge 20){
                Write-Error "The master key cannot be populated!";
                break;
            }
            sleep 1;
        }
    }

    $SetChangeKeyPassphrase.Invoke($proxy, @($sp_secure_store_passpharse_new));
    $SetKey.Invoke($proxy, @($sp_secure_store_passpharse_new));

}catch{
    Write-Error "Cannot update the secure store master key.`n{0}" -f $_.Exception.Message;
}

执行注意事项:

  • 以SharePoint服务器场管理员身份运行SharePoint Management Shell
  • 确保密码符合SharePoint密码复杂度要求

四、配置中央管理站点HTTPS访问

  1. 在IIS管理器中找到中央管理站点,右键→编辑绑定→添加HTTPS绑定,选择已有的SSL证书(或申请新证书)
  2. 执行PowerShell命令更新CA站点URL:
    $caWebApp = Get-SPWebApplication -IncludeCentralAdministration | Where-Object { $_.IsAdministrationWebApplication -eq $true }
    $caWebApp.AlternateUrls.Add("https://你的CA域名:端口", [Microsoft.SharePoint.Administration.SPUrlZone]::Default)
    $caWebApp.Update()
    
  3. 重启SharePoint Timer Service和IIS服务

五、验证Oracle数据连接

Secure Store恢复正常后,执行以下验证:

  • 检查Secure Store中存储的Oracle凭据(用户名、密码、连接字符串)是否正确
  • 确认Web部件关联的外部内容类型已绑定到正确的Secure Store目标应用
  • 在SharePoint服务器使用tnsping命令验证Oracle实例连通性

内容的提问来源于stack exchange,提问作者GeneralSiebenMC

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 15:25:18