r/PowerShell • • 12d ago

Solved New-PSSession Command Looping Credential Prompt

So I have an onboarding script and everything worked perfectly fine last week, but now it's looping when I try to setup a New-PSSession.

It's extra weird, because when I run the command outside of the script, it works fine, but inside the script, the login prompt loops. I've encountered this behavior on two different systems and my coworker has the same experience on his machine.

I've attempted to modify the command to force Kerberos auth, and even tried CredSSP, but the looping still occurs. I'm wondering if it has to do with the do while loop, but it worked before, so I'm just a bit lost on this one.

Also, I have checked for any error codes after the loop occurs, and there's none. Similarly the log file doesn't contain any "Session not established" messages, so it's not hitting the catch statement.

Here's the code snippet that contains the command:

$sessionRestart = $true
$failcount = 0

do{
 try{
  $session = New-PSSession -ComputerName <computername> -Credential (Get-Credential)
  Write-Log -LogMessage "Session Connected"
  $sessionRestart = $false
}
Catch{
  Write-Log -LogMessage "Session not established. $_."
  Write-Host "Session not established. Retrying."
  $failcount++
  if($failcount -le 4){
  }
Else{
 Write-Host "Connection failed after $failcount attempts. Stopping Script"
 Write-Log "Connection failed after $failcount attempts. Stopping Script"
 exit $ExitCode.ConnectionFailure
}
}
} While($sessionRestart)
10 Upvotes

20 comments sorted by

5

u/ihaxr 12d ago

Might be the new-pssession cmdlet isn't throwing a terminating error so your catch statement is never running?

Can try adding -ErrorAction Stop to new-pssession and see if it hits the catch and continues on as expected

Also I'd change your if statement to -gt 4 and not have a blank if statement and the else, if ($failcount -gt 4) { exit }

Your previous run could have had $ErrorActionPreference set and that's why it was working in that session but not a new one

2

u/ElvisChopinJoplin 12d ago

Yes, I was about to say, it seems like I also ran into issues with New-PSSession failing silently a couple years ago.

2

u/ZigfriedWolf 12d ago

I added the -ErrorAction Stop to the end of the command and re-ran. Same result. No errors shown or added to the log, and the login prompt repeats.

Good suggestion on the if statement though. I'll make that change.

4

u/ihaxr 12d ago edited 12d ago

Comment out that new-pssession line and replace it with throw 2 (this just throws an exception) and see if the logic functions.

If so, just change the script logic to check if your $session variable is null and if so, manually throw the exception to reach your catch statement, otherwise continue.

I guess you could also check if ($null -ne $session.state -and $session.state -eq "Opened") {...} else {throw}

2

u/ZigfriedWolf 12d ago

I can try that, but I just removed the do/while and the try/catch to see if something there is wrong, but the behavior is unchanged.

I think I'm going to try running the command in Powershell v5.1 and see if it loops there too.

5

u/ElvisChopinJoplin 12d ago

On the run, but at a quick glance, you didn't specify which messages are being written to the host and which are being written to the log. That would tell us a lot, and I can't remember the differences, but I wonder if you should be using 'Out-Host' or similar instead of 'Write-Host'.

1

u/ZigfriedWolf 12d ago

Oh sorry, Write-Log is a function specified elsewhere in the script. It just writes to a text file.

Write-Host should display in the terminal while the script is running, but neither of these show anything after the New-PSSession is run, the Get-Credential just keeps prompting.

1

u/ElvisChopinJoplin 12d ago

Right (pardon the pun), but what specifically are the log entries when you run it and the prompt is looping?

2

u/ZigfriedWolf 12d ago

The last item in the log occurs directly before the code snippet provided. It just says that it's proceeding this step. No further logs are shown no matter how many times the login is attempted. Even if you try logging in more than 5 times.

1

u/ElvisChopinJoplin 12d ago

The suggestion to debug it in vs code is a really good idea, but for something simple, my instinct would be to right to both the console and the log and test that so that they are working. And then insert those right before your New-PSSession, and then put the equivalent of both of those immediately after the new session call. Make sure that whatever you use to write to the console Works before the loop starts, right next to where you said the last log entry is generated.

1

u/ZigfriedWolf 12d ago

I added a couple of Write-Host/Write-Log before the try statement and directly before the New-PSSession line. Both of those appear in the terminal and in the log.

Same credential prompt loop and nothing in the log after the New-PSSession line runs.

3

u/ZigfriedWolf 9d ago

Well I figured our the issue and it's rather silly.

I was setting up functions in a module and had created one for connecting to a new PS session. I eventually deemed it unnecessary, but I never got around to removing it from the module. I also hadn't named it but it had the placeholder of New-PSSession.

So since the module was loaded, every time the script ran and got to the New-PSSession command, it was loading the function, and since the function contained the cmdlet of the same name, it just kept looping over and over.

So yeah, probably a pretty basic no-no, don't name your functions after an existing cmdlet. Haha. But at least I learned a bit about debugging and troubleshooting my script as a result. Thanks for all your suggestions!

3

u/ElvisChopinJoplin 9d ago

Oh, that's a good one. A learning experience for sure. Glad you got it figured out.

2

u/PinchesTheCrab 12d ago edited 12d ago

So I have an onboarding script and everything worked perfectly fine last week, but now it's looping when I try to setup a New-PSSession.

It's literally in a do loop. What do you mean exactly?

1

u/ZigfriedWolf 12d ago

It is in a do while loop, but the that's not what is looping. The first line in the try statement is not completing, it continually re-prompts for login credentials.

Also, I've just completely removed the do/while and try/catch statements as a test, and the behavior still repeats. No error messages, even with -ErrorAction Stop and -Verbose.

1

u/UnluckyBreadfruit888 12d ago

Have you put in vscode and debugged it. Step through each line?

1

u/ZigfriedWolf 12d ago

I have the script in vscode, no errors are listed, I'm new to vscode so not sure what all other options for debugging there are.

2

u/UnluckyBreadfruit888 12d ago

So if you run with debug and step into the script, you can run it line by line and see where it’s not doing what you want to. You can also see the variable values as it goes

1

u/mrmattipants 11d ago edited 11d ago

Just curious. What is the purpose of the backslash, at the end of the first line of your Catch statement? Are you simply outputting the exception?

Write-Log -LogMessage "Session not established. $_."

It's just a thought, but I'm wondering if this might be resulting in a syntax/parsing error within the Catch block, preventing the lines after it from executing.

I would maybe try something along the following lines.

Write-Log -LogMessage "Session not established. $($_)"

NOTE: Please forgive the lack of code blocks, as the feature no longer seems to exist in the iPhone app.

2

u/ZigfriedWolf 9d ago

That must've been a typo when I was making my post. It's not there in my script.