PowerShell / PowerShell/PowerShell-Docker

Proxy authentication from Ubuntu 24.04. fails for Install-PSResource with error code 407

オープン
#847 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

主要言語
Dockerfile
スター
449
フォーク
158
平均マージ
3日 10時間
マージ済み PR(30日)
1

説明

Prerequisites
  • Write a descriptive title.
  • Make sure you are able to repro it on the latest image.
  • Search the existing issues.
  • Verified that this is not a Known Issue
  • Verified this is not an issues in the underlying windows container that should be reported to Windows Feedback Hub
Steps to reproduce

Under powershell:preview-ubuntu-24.04, we cannot get NTLM authentication with our HTTP(S) proxy to work. Therefore, we cannot install PowerShell modules. We supply the proxy credentials via en environment variable (which seems to be picked up).

docker run -e ALL_PROXY="http://<username>:<pw>@<proxyfqdn>:8080" --rm --name pwsh -it mcr.microsoft.com/powershell:preview-ubuntu-24.04

I believe we are hitting https://github.com/dotnet/runtime/issues/100231. Our Wireshark capture shows a first CONNECT to the proxy to be initiated without authentication. A second CONNECT is initiated with a Proxy-Authorization header, but that still returns 407.

The Ubuntu 22.04 and Alpine 3.20 images behave differently, there the second CONNECT message is not send at all. I believe these hit NTLM authentication not working in Linux based environment · Issue #101058 · dotnet/runtime instead.

Proxy authentication under Windows works.

Expected behavior
Az Module is installed.
Actual behavior
PS /> [System.Net.Http.HttpClient]::DefaultProxy

Credentials
-----------
System.Net.Http.HttpEnvironmentProxyCredentials

PS /> Install-PSResource -Name Az -Scope CurrentUser

Untrusted repository
You are installing the modules from an untrusted repository. If you trust this repository, change its Trusted value by running the Set-PSResourceRepository cmdlet. Are you sure you want to install the
PSResource from 'PSGallery'?
[Y] Yes  [A] Yes to All  [N] No  [L] No to All  [S] Suspend  [?] Help (default is "N"): A
Install-PSResource: 'The proxy tunnel request to proxy 'http://<user>:<pw>@<proxyfqdn>:8080/' failed with status code '407'."' Request sent: 'https://www.powershellgallery.com/api/v2/FindPackagesById()?%24filter=Id+eq+%27Az%27+and+IsLatestVersion+eq+true&%24inlinecount=allpages&id=%27Az%27'
Install-PSResource: Package(s) 'Az' could not be installed from repository 'PSGallery'.
Error details
PS /> Get-Error

Exception             :
    Type    : Microsoft.PowerShell.PSResourceGet.UtilClasses.ResourceNotFoundException
    Message : Package(s) 'Az' could not be installed from repository 'PSGallery'.
    HResult : -2146233088
TargetObject          : Microsoft.PowerShell.PSResourceGet.Cmdlets.InstallPSResource
CategoryInfo          : InvalidData: (Microsoft.PowerShel…s.InstallPSResource:InstallPSResource) [Install-PSResource], ResourceNotFoundException
FullyQualifiedErrorId : InstallPackageFailure,Microsoft.PowerShell.PSResourceGet.Cmdlets.InstallPSResource
InvocationInfo        :
    MyCommand        : Install-PSResource
    ScriptLineNumber : 1
    OffsetInLine     : 1
    HistoryId        : 3
    Line             : Install-PSResource -Name Az -Scope CurrentUser
    Statement        : Install-PSResource -Name Az -Scope CurrentUser
    PositionMessage  : At line:1 char:1
                       + Install-PSResource -Name Az -Scope CurrentUser
                       + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    InvocationName   : Install-PSResource
    CommandOrigin    : Internal
ScriptStackTrace      : at <ScriptBlock>, <No file>: line 1
PipelineIterationInfo :
      0
      1
Environment data
{
        "schemaVersion": 2,
        "mediaType": "application/vnd.docker.distribution.manifest.v2+json",
        "config": {
                "mediaType": "application/vnd.docker.container.image.v1+json",
                "size": 5572,
                "digest": "sha256:ca17b51e4e0fbd04c97c1a6ee9109a505c425f63a8c9ca1b80a6c908035a74c5"
        },
        "layers": [
                {
                        "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
                        "size": 29751968,
                        "digest": "sha256:de44b265507ae44b212defcb50694d666f136b35c1090d9709068bc861bb2d64"
                },
                {
                        "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
                        "size": 103040902,
                        "digest": "sha256:94058be39bdeb7bdadb5c92c6d989191e021a35d7d7a24d27f5fbe1cce3439d6"
                }
        ]
}
Visuals

No response

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

まず、preview-ubuntu-24.04 イメージ上でプロキシ環境変数を指定した docker run コマンドを再現し、その後 Ubuntu 22.04 および Alpine 3.20 イメージと比較します。リンクされた dotnet/runtime の issue で説明されている NTLM プロキシの動作を調査します。Install-PSResource -Name Az が認証済みプロキシ経由で成功すれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
docker, powershell, ubuntu
領域
authentication, infrastructure, networking
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
28/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。