使用PowerShell脚本下载执行文件时遇SSL/TLS安全通道创建失败问题
Hey there, let's get that SSL/TLS error sorted out for your PowerShell script. This issue is super common, and it almost always stems from older TLS versions being disabled by default in .NET (which System.Net.WebClient depends on)—most modern servers now only support TLS 1.2 or later, but .NET doesn't enable these by default in older PowerShell environments.
Quick Fix: Enable Modern TLS Versions
Add a line at the very start of your script to force .NET to use TLS 1.2 and 1.3. Here's your updated script:
# Enable modern TLS protocols to avoid secure channel errors [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 -bor [Net.SecurityProtocolType]::Tls13 $down = New-Object System.Net.WebClient $url = 'your-target-url-here' # Replace with your actual URL $file = 'your-output-file-path' # Replace with your desired file path $down.DownloadFile($url,$file) $exec = New-Object -com shell.application $exec.shellexecute($file) exit
Why this works:
By default, older PowerShell environments use .NET configurations that only enable outdated TLS 1.0 and 1.1. Most websites and servers have dropped support for these versions due to security vulnerabilities, so explicitly setting SecurityProtocol to include TLS 1.2 and 1.3 lets your script establish a valid secure connection.
If the Quick Fix Doesn't Work: Additional Troubleshooting Steps
- Check the target URL's certificate: Make sure the server's SSL certificate is valid (not expired, issued by a trusted CA, and matches the domain). If it's a self-signed certificate (common in internal environments), you might need to add it to your system's trusted root store—but only do this if you fully trust the source.
- Verify system-level TLS settings: Ensure TLS 1.2 and 1.3 aren't disabled on your Windows machine via Group Policy or registry settings. You can check this in the Internet Options > Advanced tab, under the "Security" section.
- Switch to a modern HTTP client:
System.Net.WebClientis legacy technology. Try usingInvoke-WebRequest(PowerShell's modern alternative) instead—it handles modern TLS configurations more reliably. Here's a rewritten version of your script:
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 -bor [Net.SecurityProtocolType]::Tls13 Invoke-WebRequest -Uri 'your-target-url-here' -OutFile 'your-output-file-path' Start-Process 'your-output-file-path' exit
Start-Process is also a more native PowerShell alternative to Shell.Application.ShellExecute, so it might behave more predictably across different Windows versions.
内容的提问来源于stack exchange,提问作者kate maran

