如何解决PowerShell远程跨服务器拷贝文件的双跳权限问题
跨设备远程拷贝文件的凭证问题(使用Start-BitsTransfer)
背景
远程办公整体运行正常,但偶尔需要在服务器间或从供应商网站向服务器拷贝大文件/大量文件,家用ISP上传速度有限导致耗时极长。希望借助PowerShell远程执行能力,通过中间设备跨任意有权限的设备拷贝文件,偏好使用Start-BitsTransfer工具,因其速度更快且支持从供应商网站下载软件。
本地登录服务器执行正常
通过远程桌面登录server1执行以下代码,可正常将server2的c:\myfolder文件拷贝到server1的对应目录:
$src = "\\server2\c$\myfolder\*" $dest = "c:\myfolder\" [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 Start-BitsTransfer -Source $src -Destination $dest
本地工作站远程调用脚本无反应
尝试通过本地工作站执行RemoteCopy.ps1脚本(借助Invoke-Command远程调用server1执行拷贝)时无任何反应:
RemoteCopy.ps1 脚本内容
param( [string]$computer, [string]$source, [string]$destination ) Invoke-Command -ComputerName $computer -ScriptBlock { $src = $args[0] $dest = $args[1] [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 Start-BitsTransfer -Source $src -Destination $dest #Copy-Item -Path $src -Destination $dest } -ArgumentList $source,$destination
本地执行命令
.\RemoteCopy.ps1 -computer server1 -source "\\server2\c$\myfolder\*" -destination "c:\myfolder\"
添加凭证后的报错信息
工作站、server1、server2同属一个域,账号在三台设备上均为管理员,使用PowerShell 5.1。尝试添加Credential参数、在Start-BitsTransfer中传入Credential均报错:
The operation being requested was not performed because the user has not logged on to the network. The specified service does not exist. (Exception from HRESULT: 0x800704DD) + CategoryInfo : NotSpecified: (:) [Start-BitsTransfer], COMException + FullyQualifiedErrorId : System.Runtime.InteropServices.COMException,Microsoft.BackgroundIntelligentTransfer.Management.NewBits TransferCommand + PSComputerName : server1
已尝试的方案及顾虑
参考Double-hop问题解决方案,注册PSSessionConfiguration后仍报错,且了解到CredSSP存在安全风险需咨询安全团队,暂不考虑使用。
提问
若为凭证问题(无报错提示的场景),该如何解决?
内容的提问来源于stack exchange,提问作者dougp
相关产品推荐
相关产品推荐

