SSH登录Windows执行NuGet SetApiKey报CryptographicException访问被拒绝
NuSet SetApiKey在Windows SSH会话中报错Access is denied的解决方案
问题根源
Windows SSH首次登录时仅加载简化版用户配置文件,未初始化**数据保护API(DPAPI)**所需的用户加密存储容器。NuSet的SetApiKey命令需要调用DPAPI加密密钥,因此触发权限拒绝异常;而RDP登录会完整加载用户配置文件并初始化加密上下文,后续SSH会话可复用该上下文。
方案1:强制SSH加载完整用户配置文件
修改OpenSSH配置,让SSH登录时自动加载完整用户配置文件,从根源解决DPAPI初始化问题:
- 修改注册表配置:
reg add HKLM\SOFTWARE\OpenSSH /v DefaultShellCommandOption /t REG_DWORD /d 2 /f
- 重启OpenSSH服务:
Restart-Service sshd
Ansible自动化实现:
- name: Configure SSH to load full user profile win_regedit: path: HKLM:\SOFTWARE\OpenSSH name: DefaultShellCommandOption data: 2 type: dword state: present - name: Restart OpenSSH Server service win_service: name: sshd state: restarted
方案2:预初始化DPAPI加密上下文
如果无法修改SSH全局配置,可在执行NuSet命令前,手动触发DPAPI初始化:
运行PowerShell命令初始化加密容器:
$null = [System.Security.Cryptography.ProtectedData]::Protect([byte[]]@(), $null, [System.Security.Cryptography.DataProtectionScope]::CurrentUser)
Ansible自动化实现:
- name: Initialize DPAPI context for build user win_shell: | $null = [System.Security.Cryptography.ProtectedData]::Protect([byte[]]@(), $null, [System.Security.Cryptography.DataProtectionScope]::CurrentUser) become: yes become_user: build - name: Set NuGet API Key win_shell: | nuget.exe SetApiKey -Verbosity detailed -Source https://some.domain.tld/v3/index.json somePassword123 become: yes become_user: build
方案3:禁用NuSet密钥加密(不推荐)
仅适合测试环境,会明文存储API密钥:
编辑用户的NuGet.Config(路径:C:\Users\build\AppData\Roaming\NuGet\NuGet.Config),添加禁用加密的配置:
<configuration> <config> <add key="disablePasswordEncryption" value="true" /> </config> </configuration>
Ansible自动化实现:
- name: Disable NuGet password encryption win_lineinfile: path: C:\Users\build\AppData\Roaming\NuGet\NuGet.Config insertafter: '<configuration>' line: ' <config><add key="disablePasswordEncryption" value="true" /></config>' state: present become: yes become_user: build
内容的提问来源于stack exchange,提问作者Jonatan Wallmander
相关产品推荐
相关产品推荐

