使用PowerShell在远程服务器安装MSI程序无响应问题求助
PowerShell脚本远程部署MSI无响应问题解决方案
核心问题根因
- 最主要原因是Kerberos双跳限制:通过
Invoke-Command建立的远程PowerShell会话,默认无法将你的身份凭据二次转发到第三方SMB共享(也就是脚本中使用的\\mylocalbox\C$\Splunk.msi),远程服务器上的运行会话没有权限访问该安装包路径。此时msiexec进程处于等待资源的挂起状态,还没进入安装逻辑,所以不会生成日志、也没有安装痕迹,同时因为脚本加了-Wait参数,会一直卡住等待进程结束。 - 其他潜在影响问题:
- 远程服务器的
C:\temp目录不存在:msiexec指定的日志父目录如果不存在,会直接执行失败,也不会生成日志文件。 - 传入的安装路径带尾部反斜杠,拼接参数时可能会意外转义后续引号,导致msiexec参数解析错误。
- 远程服务器的
修复方案
方案1:提前复制安装包到远程服务器(最稳定,推荐)
该方案不需要修改系统安全配置,兼容性最好,修改后完整脚本如下:
$Cred = Get-Credential $Computer = 'myserver.contoso.com' # 本地存储的Splunk安装包路径 $LocalSplunkMSI = 'C:\Splunk.msi' $InstallDir = 'C:\Apps\Splunk' $RemoteTempDir = 'C:\Temp\' $RemoteMSIPath = Join-Path $RemoteTempDir 'Splunk.msi' # 提前在远程服务器创建临时目录 Invoke-Command -ComputerName $Computer -Credential $Cred -ScriptBlock { param($TempDir) if (-not (Test-Path $TempDir)) { New-Item -Path $TempDir -ItemType Directory -Force | Out-Null } } -ArgumentList $RemoteTempDir -ErrorAction Stop # 直接将本地安装包复制到远程服务器,不需要依赖SMB共享二次访问 Copy-Item -Path $LocalSplunkMSI -Destination "\\$Computer\C$\Temp\" -Credential $Cred -Force $sb = { param($installer, $dir) $installProcess = Start-Process -FilePath 'msiexec.exe' -ArgumentList "/i $installer INSTALLDIR=`"$dir`" AGREETOLICENSE=Yes /qn /norestart /L*v C:\temp\splunkInstall.log" -Wait -NoNewWindow -PassThru # 返回执行结果方便本地排查 return [PSCustomObject]@{ ExitCode = $installProcess.ExitCode LogPath = 'C:\temp\splunkInstall.log' } } Write-Host "Deploying Splunk to host $Computer" $installResult = Invoke-Command -Computer $Computer -Credential $Cred -ScriptBlock $sb -ArgumentList $RemoteMSIPath, $InstallDir -ErrorAction Stop Write-Host "Installation finished, exit code: $($installResult.ExitCode), log path on remote host: $($installResult.LogPath)"
方案2:配置CredSSP绕过双跳限制(不推荐,存在安全风险)
如果必须使用共享路径的安装包,可以启用CredSSP身份验证实现凭据二次转发,操作步骤如下:
- 本地执行命令开启客户端CredSSP权限:
Enable-WSManCredSSP -Role Client -DelegateComputer $Computer -Force - 远程服务器执行命令开启服务端CredSSP权限:
Invoke-Command -ComputerName $Computer -Credential $Cred -ScriptBlock {Enable-WSManCredSSP -Role Server -Force} - 原有脚本的
Invoke-Command执行时增加参数-Authentication CredSSP即可。
排查注意事项
- msiexec静默执行的退出码可直接用于判断结果:0代表安装成功,1619代表找不到安装包,1603代表通用安装错误,可对应返回的退出码快速定位问题。
- 安装路径参数建议用双引号包裹,避免路径包含空格时出现参数解析错误。
- 批量部署时可将服务器名存入数组循环执行即可。
内容的提问来源于stack exchange,提问作者Mike Bruno
相关产品推荐
相关产品推荐

