Windows Server 2022 WinRM证书认证遇401错误求助
Windows Server 2022 WinRM证书认证故障排查
环境:
- Windows Server 2022(CIS STIGs镜像),已运行WinRM服务
- Ubuntu Pro 20.04 FIPS客户端,使用pywinrm v0.5.0连接
- 双方证书为ACM PCA自签名,CA证书已添加至Windows和Ubuntu信任存储
1. Windows Server 2022端配置
PS C:\Windows\system32> Get-ChildItem -Path Cert:\CurrentUser\Root | Where-Object { $_.Thumbprint -eq "5A2F4E63BEBEDB186ED84BF722B54207E6664469" } | Select-Object Subject, Thumbprint Subject Thumbprint ------- ---------- L=TA, CN=example.com, S=TA, OU=RnD, O=Company, C=IL 5A2F4E63BEBEDB186ED84BF722B54207E6664469 PS C:\Windows\system32> winrm enumerate winrm/config/service/certmapping CertMapping URI = * Subject = 50612F90702F2FEF1B777E987B7CD974DC99CE51 Issuer = 5A2F4E63BEBEDB186ED84BF722B54207E6664469 UserName = Administrator Enabled = true Password PS C:\Windows\system32> winrm g winrm/config Config MaxEnvelopeSizekb = 500 MaxTimeoutms = 1800000 MaxBatchItems = 32000 MaxProviderRequests = 4294967295 Client NetworkDelayms = 5000 URLPrefix = wsman AllowUnencrypted = false [Source="GPO"] Auth Basic = false [Source="GPO"] Digest = false [Source="GPO"] Kerberos = true Negotiate = true Certificate = true CredSSP = false DefaultPorts HTTP = 5985 HTTPS = 5986 TrustedHosts Service RootSDDL = O:NSG:BAD:P(A;;GA;;;BA)(A;;GR;;;IU)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD) MaxConcurrentOperations = 4294967295 MaxConcurrentOperationsPerUser = 1500 EnumerationTimeoutms = 240000 MaxConnections = 300 MaxPacketRetrievalTimeSeconds = 120 AllowUnencrypted = false [Source="GPO"] Auth Basic = false [Source="GPO"] Kerberos = true Negotiate = true Certificate = true CredSSP = true CbtHardeningLevel = Relaxed DefaultPorts HTTP = 5985 HTTPS = 5986 IPv4Filter = * IPv6Filter = * EnableCompatibilityHttpListener = false EnableCompatibilityHttpsListener = true CertificateThumbprint AllowRemoteAccess = true Winrs AllowRemoteShellAccess = true IdleTimeout = 7200000 MaxConcurrentUsers = 2147483647 MaxShellRunTime = 2147483647 MaxProcessesPerShell = 2147483647 MaxMemoryPerShellMB = 1024 MaxShellsPerUser = 2147483647 PS C:\Windows\system32> winrm g winrm/config/service Service RootSDDL = O:NSG:BAD:P(A;;GA;;;BA)(A;;GR;;;IU)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD) MaxConcurrentOperations = 4294967295 MaxConcurrentOperationsPerUser = 1500 EnumerationTimeoutms = 240000 MaxConnections = 300 MaxPacketRetrievalTimeSeconds = 120 AllowUnencrypted = false [Source="GPO"] Auth Basic = false [Source="GPO"] Kerberos = true Negotiate = true Certificate = true CredSSP = true CbtHardeningLevel = Relaxed DefaultPorts HTTP = 5985 HTTPS = 5986 IPv4Filter = * IPv6Filter = * EnableCompatibilityHttpListener = false EnableCompatibilityHttpsListener = true CertificateThumbprint = 13F3C1844B7617270D1331BEB02AD347FAB74D9C AllowRemoteAccess = true
2. Ubuntu Pro 20.04端配置
$ cert_path="/etc/nginx/certs/controller.example.com.crt.pem" $ thumbprint=$(openssl x509 -in "$cert_path" -noout -fingerprint -sha1 | sed 's/://g' | awk -F= '{print $2}') $ echo $thumbprint 50612F90702F2FEF1B777E987B7CD974DC99CE51 $ issuer_thumbprint=$(tac /etc/ssl/certs/ca-certificates.crt | awk 'BEGIN {c=0} /END CERTIFICATE/ {c++} {if (c==1) print}' | tac | openssl x509 -in /dev/stdin -noout -fingerprint -sha1 | sed 's/://g' | awk -F= '{print $2}') $ echo $issuer_thumbprint 5A2F4E63BEBEDB186ED84BF722B54207E6664469
3. 连接测试错误
$ python -c "import winrm; winrm.Session('https://winrm.example.com:5986/wsman', auth=(None, None), transport='certificate', cert_key_pem='/etc/nginx/certs/controller.example.com.key.pem', cert_pem='/etc/nginx/certs/controller.example.com.crt.pem', server_cert_validation='validate', ca_trust_path='/etc/ssl/certs/ca-certificates.crt').run_cmd('ipconfig', ['/all']).std_out.decode()" Traceback (most recent call last): File "/opt/venv3.11/lib/python3.11/site-packages/winrm/transport.py", line 342, in _send_message_request response.raise_for_status() File "/opt/venv3.11/lib/python3.11/site-packages/requests/models.py", line 1024, in raise_for_status raise HTTPError(http_error_msg, response=self) requests.exceptions.HTTPError: 401 Client Error: for url: https://winrm.example.com:5986/wsman During handling of the above exception, another exception occurred: Traceback (most recent call last): File "<string>", line 1, in <module> File "/opt/venv3.11/lib/python3.11/site-packages/winrm/__init__.py", line 44, in run_cmd shell_id = self.protocol.open_shell() ^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/opt/venv3.11/lib/python3.11/site-packages/winrm/protocol.py", line 193, in open_shell res = self.send_message(xmltodict.unparse(req)) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/opt/venv3.11/lib/python3.11/site-packages/winrm/protocol.py", line 263, in send_message resp = self.transport.send_message(message) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/opt/venv3.11/lib/python3.11/site-packages/winrm/transport.py", line 336, in send_message response = self._send_message_request(session, prepared_request) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/opt/venv3.11/lib/python3.11/site-packages/winrm/transport.py", line 346, in _send_message_request raise InvalidCredentialsError("the specified credentials were rejected by the server") winrm.exceptions.InvalidCredentialsError: the specified credentials were rejected by the server
4. WinRM服务日志
PS C:\Windows\system32> Get-WinEvent -LogName "Microsoft-Windows-WinRM/Operational" -MaxEvents 1 | Format-List * Message : The authorization of the user failed with error 5 Id : 192 Version : 0 Qualifiers : Level : 4 Task : 8 Opcode : 0 Keywords : 4611686018427387916 RecordId : 5435 ProviderName : Microsoft-Windows-WinRM ProviderId : a7975c8f-ac13-49f1-87da-5a984a4ab417 LogName : Microsoft-Windows-WinRM/Operational ProcessId : 3320 ThreadId : 3744 MachineName : winrm UserId : S-1-5-20 TimeCreated : 4/8/2025 8:44:41 PM ActivityId : a3ddc236-a84c-0004-90ed-dda34ca8db01 RelatedActivityId
排查建议
核心问题定位
WinRM事件ID192错误5对应ERROR_ACCESS_DENIED,说明证书映射后的用户权限不足或映射规则不匹配。
具体排查步骤
- 修正证书映射规则的Subject字段:
WinRM证书映射中,Subject应填写客户端证书的主题名称(如CN=controller.example.com),而非证书指纹。当前配置将Subject设为客户端证书指纹,这是错误的。可在Ubuntu端执行openssl x509 -in "$cert_path" -noout -subject获取正确值,然后更新映射规则:winrm delete winrm/config/service/certmapping?Subject=50612F90702F2FEF1B777E987B7CD974DC99CE51 winrm create winrm/config/service/certmapping '@{URI="*";Subject="CN=controller.example.com";Issuer="5A2F4E63BEBEDB186ED84BF722B54207E6664469";UserName="Administrator";Enabled="true"}' - 验证管理员WinRM权限:
检查映射的Administrator用户是否具备WinRM远程访问权限:
确保Builtin\Administrators组拥有Get-PSSessionConfiguration -Name Microsoft.PowerShell | Select-Object PermissionFullControl权限,若缺失可执行:Set-PSSessionConfiguration -Name Microsoft.PowerShell -ShowSecurityDescriptorUI - 调整CA证书存储位置:
WinRM服务运行在本地系统账户下,需将CA证书导入LocalMachine\Root存储,而非CurrentUser\Root:Import-Certificate -FilePath "C:\path\to\ca.crt" -CertStoreLocation "Cert:\LocalMachine\Root" - 适配FIPS模式加密要求:
Ubuntu处于FIPS模式,需确保客户端证书使用FIPS合规算法(如SHA256)。重新生成SHA256指纹并更新映射规则:# Ubuntu端生成SHA256指纹 thumbprint=$(openssl x509 -in "$cert_path" -noout -fingerprint -sha256 | sed 's/://g' | awk -F= '{print $2}') - 确认WinRM HTTPS监听证书有效性:
检查WinRM绑定的证书(指纹13F3C1844B7617270D1331BEB02AD347FAB74D9C)是否在LocalMachine\My存储中,且证书的Subject或SAN包含winrm.example.com。
内容的提问来源于stack exchange,提问作者shachar0n
相关产品推荐
相关产品推荐

