Azure云服务部署报错:请求的注册表访问未被允许
根据你提供的IntelliTrace日志,问题核心是ASP.NET进程尝试访问Security事件日志对应的注册表项,但没有足够权限,导致进程启动受阻。既然无法降级到.NET 4.5.1,这里有两个可行的解决方案:
方案一:通过启动任务配置注册表权限
Azure Web角色允许通过高权限启动任务修改虚拟机的注册表权限,让ASP.NET运行的NETWORK SERVICE账户能访问目标注册表项:
- 创建批处理文件
SetupRegistry.cmd,内容如下:@echo off rem 使用regini工具配置注册表权限 regini SecurityRegPermissions.ini - 创建权限配置文件
SecurityRegPermissions.ini,定义NETWORK SERVICE对Security日志注册表项的读取权限:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Security [1 5 7 11] ; 权限解释: ; 1 = 管理员完全控制 ; 5 = NETWORK SERVICE 读取权限 ; 7 = SYSTEM 完全控制 ; 11 = Everyone 读取权限 - 在云服务的
ServiceDefinition.csdef中添加启动任务配置(确保任务以管理员权限执行):
部署时,这个任务会在角色启动前执行,自动配置好所需的注册表权限。<WebRole name="YourWebRoleName" vmsize="Small"> <Startup> <Task commandLine="SetupRegistry.cmd" executionContext="elevated" taskType="simple" /> </Startup> <!-- 其他角色配置(站点、端点等) --> </WebRole>
方案二:排查并移除不必要的Security日志访问
如果你的代码没有主动操作Security事件日志,那可能是框架或第三方组件的默认行为导致的:
- 检查
web.config中的<system.diagnostics>节点,是否配置了指向Security日志的EventLogTraceListener,如果有,将其修改为Application或System日志。 - 搜索代码中的
EventLog.WriteEntry调用,确认是否有指定日志名称为Security的情况,将其改为Application(普通应用程序有权限写入这个日志)。 - 排查近期添加的NuGet包,确认是否有组件自动尝试访问Security日志,必要时替换或禁用该组件的相关功能。
附你提供的异常日志片段:
激活事件 事件时间(UTC+00:00) 线程
Registry: Opening "Windows Azure Runtime 2.7.0.0". 尝试打开注册表项"Windows Azure Runtime 2.7.0.0". 1/9/2018 6:07:11 AM [2672]
激活事件 事件时间(UTC+00:00) 线程
Registry: Opened "". 尝试打开注册表项""。若尝试失败,返回null。要确定访问的是哪个项,请查看此线程中的上一个诊断事件。1/9/2018 6:07:11 AM [2672]
激活事件 事件时间(UTC+00:00) 线程
Registry: Closed "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Key Management Service". 关闭注册表项"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Key Management Service". 1/9/2018 6:07:11 AM [2672]
激活事件 事件时间(UTC+00:00) 线程
Registry: Opening "Security". 尝试打开注册表项"Security". 1/9/2018 6:07:11 AM [2672]
激活事件 事件时间(UTC+00:00) 线程
Exception: Exception thrown: 'System.Security.SecurityException' in CommonLanguageRuntimeLibrary ("Requested registry access is not allowed.") 抛出异常:'System.Security.SecurityException' in CommonLanguageRuntimeLibrary("Requested registry access is not allowed.")1/9/2018 6:07:11 AM [2672]
激活事件 事件时间(UTC+00:00) 线程
Exception: Exception caught: 'System.Security.SecurityException' in System.dll ("Requested registry access is not allowed.") 捕获异常:'System.Security.SecurityException' in System.dll("Requested registry access is not allowed.")1/9/2018 6:07:11 AM [2672]
激活事件 事件时间(UTC+00:00) 线程
Registry: Opening "System". 尝试打开注册表项"System". 1/9/2018 6:07:11 AM [2672]
激活事件 事件时间(UTC+00:00) 线程
Registry: Opened "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System". 尝试打开注册表项"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System"。若尝试失败,返回null。要确定访问的是哪个项,请查看此线程中的上一个诊断事件。1/9/2018 6:07:11 AM [2672]
内容的提问来源于stack exchange,提问作者Jeppe

