You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 20.04 LTS下Connect-AzAccount SSL连接失败求助

Ubuntu 20.04 LTS中PowerShell连接Azure失败(SSL连接问题)

系统重置后在Ubuntu 20.04 LTS重新配置环境,安装PowerShell(pwsh)后,执行Connect-AzAccount命令连接Azure门户失败,报错:

Connect-AzAccount: InteractiveBrowserCredential authentication failed: Retry failed after 4 tries. Retry settings can be adjusted in ClientOptions.Retry. (The SSL connection could not be established, see inner exception.) (The SSL connection could not be established, see inner exception.) (The SSL connection could not be established, see inner exception.) (The SSL connection could not be established, see inner exception.)

随后尝试用户名密码脚本登录:

$User = "xxx@xxxx.onmicrosoft.com"
$PWord = ConvertTo-SecureString -String "<Password>" -AsPlainText -Force
$tenant = "<tenant id>"
$subscription = "<subscription id>"
$Credential = New-Object -TypeName "System.Management.Automation.PSCredential" -ArgumentList $User,$PWord
Connect-AzAccount -Credential $Credential -Tenant $tenant -Subscription $subscription

仍失败,报错:

Connect-AzAccount: UsernamePasswordCredential authentication failed: Retry failed after 4 tries. Retry settings can be adjusted in ClientOptions.Retry. (The SSL connection could not be established, see inner exception.) (The SSL connection could not be established, see inner exception.) (The SSL connection could not be established, see inner exception.) (The SSL connection could not be established, see inner exception.) See the troubleshooting guide for more information. https://aka.ms/azsdk/net/identity/usernamepasswordcredential/troubleshoot


排查与解决步骤

1. 修复系统SSL根证书

Ubuntu 20.04的根证书缺失或损坏会导致SSL握手失败,执行以下命令更新证书:

sudo apt update && sudo apt install --reinstall ca-certificates
sudo update-ca-certificates

2. 验证网络连通性与代理配置

  • 测试Azure身份验证端点的连通性:
    curl -v https://login.microsoftonline.com
    
  • 若使用代理,需在PowerShell中配置代理环境变量:
    $env:HTTP_PROXY = "http://your-proxy-address:port"
    $env:HTTPS_PROXY = "http://your-proxy-address:port"
    
    如果代理使用自签名证书,需将证书添加到系统信任列表中。

3. 更新PowerShell与Az模块

旧版本可能存在SSL兼容性问题:

  • 更新PowerShell:
    sudo apt update && sudo apt upgrade powershell
    
  • 更新Az模块:
    Update-Module -Name Az -Force -AllowClobber
    

4. 确保系统时间同步

SSL握手对时间精度要求高,修复时间同步:

sudo timedatectl set-ntp on
sudo systemctl restart systemd-timesyncd
timedatectl status

5. 切换到服务主体登录(替代方案)

若用户名密码方式仍无法解决,可使用Azure服务主体登录:

  1. 在Azure门户创建服务主体,获取client-id、client-secret、tenant-id
  2. 执行PowerShell命令:
    $clientSecret = ConvertTo-SecureString "<client-secret>" -AsPlainText -Force
    $credential = New-Object System.Management.Automation.PSCredential("<client-id>", $clientSecret)
    Connect-AzAccount -ServicePrincipal -Credential $credential -Tenant "<tenant-id>"
    

内容的提问来源于stack exchange,提问作者Muhammad_Bilal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 01:46:09