You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server 2022 WinRM证书认证遇401错误求助

Windows Server 2022 WinRM证书认证故障排查

环境:

  • Windows Server 2022(CIS STIGs镜像),已运行WinRM服务
  • Ubuntu Pro 20.04 FIPS客户端,使用pywinrm v0.5.0连接
  • 双方证书为ACM PCA自签名,CA证书已添加至Windows和Ubuntu信任存储

1. Windows Server 2022端配置

PS C:\Windows\system32> Get-ChildItem -Path Cert:\CurrentUser\Root | Where-Object { $_.Thumbprint -eq "5A2F4E63BEBEDB186ED84BF722B54207E6664469" } | Select-Object Subject, Thumbprint

Subject                                                                    Thumbprint
-------                                                                    ----------
L=TA, CN=example.com, S=TA, OU=RnD, O=Company, C=IL 5A2F4E63BEBEDB186ED84BF722B54207E6664469

PS C:\Windows\system32> winrm enumerate winrm/config/service/certmapping
CertMapping
    URI = *
    Subject = 50612F90702F2FEF1B777E987B7CD974DC99CE51
    Issuer = 5A2F4E63BEBEDB186ED84BF722B54207E6664469
    UserName = Administrator
    Enabled = true
    Password

PS C:\Windows\system32> winrm g winrm/config
Config
    MaxEnvelopeSizekb = 500
    MaxTimeoutms = 1800000
    MaxBatchItems = 32000
    MaxProviderRequests = 4294967295
    Client
        NetworkDelayms = 5000
        URLPrefix = wsman
        AllowUnencrypted = false [Source="GPO"]
        Auth
            Basic = false [Source="GPO"]
            Digest = false [Source="GPO"]
            Kerberos = true
            Negotiate = true
            Certificate = true
            CredSSP = false
        DefaultPorts
            HTTP = 5985
            HTTPS = 5986
        TrustedHosts
    Service
        RootSDDL = O:NSG:BAD:P(A;;GA;;;BA)(A;;GR;;;IU)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)
        MaxConcurrentOperations = 4294967295
        MaxConcurrentOperationsPerUser = 1500
        EnumerationTimeoutms = 240000
        MaxConnections = 300
        MaxPacketRetrievalTimeSeconds = 120
        AllowUnencrypted = false [Source="GPO"]
        Auth
            Basic = false [Source="GPO"]
            Kerberos = true
            Negotiate = true
            Certificate = true
            CredSSP = true
            CbtHardeningLevel = Relaxed
        DefaultPorts
            HTTP = 5985
            HTTPS = 5986
        IPv4Filter = *
        IPv6Filter = *
        EnableCompatibilityHttpListener = false
        EnableCompatibilityHttpsListener = true
        CertificateThumbprint
        AllowRemoteAccess = true
    Winrs
        AllowRemoteShellAccess = true
        IdleTimeout = 7200000
        MaxConcurrentUsers = 2147483647
        MaxShellRunTime = 2147483647
        MaxProcessesPerShell = 2147483647
        MaxMemoryPerShellMB = 1024
        MaxShellsPerUser = 2147483647

PS C:\Windows\system32> winrm g winrm/config/service
Service
    RootSDDL = O:NSG:BAD:P(A;;GA;;;BA)(A;;GR;;;IU)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)
    MaxConcurrentOperations = 4294967295
    MaxConcurrentOperationsPerUser = 1500
    EnumerationTimeoutms = 240000
    MaxConnections = 300
    MaxPacketRetrievalTimeSeconds = 120
    AllowUnencrypted = false [Source="GPO"]
    Auth
        Basic = false [Source="GPO"]
        Kerberos = true
        Negotiate = true
        Certificate = true
        CredSSP = true
        CbtHardeningLevel = Relaxed
    DefaultPorts
        HTTP = 5985
        HTTPS = 5986
    IPv4Filter = *
    IPv6Filter = *
    EnableCompatibilityHttpListener = false
    EnableCompatibilityHttpsListener = true
    CertificateThumbprint = 13F3C1844B7617270D1331BEB02AD347FAB74D9C
    AllowRemoteAccess = true

2. Ubuntu Pro 20.04端配置

$ cert_path="/etc/nginx/certs/controller.example.com.crt.pem"
$ thumbprint=$(openssl x509 -in "$cert_path" -noout -fingerprint -sha1 | sed 's/://g' | awk -F= '{print $2}')
$ echo $thumbprint
50612F90702F2FEF1B777E987B7CD974DC99CE51

$ issuer_thumbprint=$(tac /etc/ssl/certs/ca-certificates.crt | awk 'BEGIN {c=0} /END CERTIFICATE/ {c++} {if (c==1) print}' | tac | openssl x509 -in /dev/stdin  -noout -fingerprint -sha1 | sed 's/://g' | awk -F= '{print $2}')
$ echo $issuer_thumbprint
5A2F4E63BEBEDB186ED84BF722B54207E6664469

3. 连接测试错误

$ python -c "import winrm; winrm.Session('https://winrm.example.com:5986/wsman', auth=(None, None), transport='certificate', cert_key_pem='/etc/nginx/certs/controller.example.com.key.pem', cert_pem='/etc/nginx/certs/controller.example.com.crt.pem', server_cert_validation='validate', ca_trust_path='/etc/ssl/certs/ca-certificates.crt').run_cmd('ipconfig', ['/all']).std_out.decode()"
Traceback (most recent call last):
  File "/opt/venv3.11/lib/python3.11/site-packages/winrm/transport.py", line 342, in _send_message_request
    response.raise_for_status()
  File "/opt/venv3.11/lib/python3.11/site-packages/requests/models.py", line 1024, in raise_for_status
    raise HTTPError(http_error_msg, response=self)
requests.exceptions.HTTPError: 401 Client Error:  for url: https://winrm.example.com:5986/wsman

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "<string>", line 1, in <module>
  File "/opt/venv3.11/lib/python3.11/site-packages/winrm/__init__.py", line 44, in run_cmd
    shell_id = self.protocol.open_shell()
               ^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/opt/venv3.11/lib/python3.11/site-packages/winrm/protocol.py", line 193, in open_shell
    res = self.send_message(xmltodict.unparse(req))
          ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/opt/venv3.11/lib/python3.11/site-packages/winrm/protocol.py", line 263, in send_message
    resp = self.transport.send_message(message)
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/opt/venv3.11/lib/python3.11/site-packages/winrm/transport.py", line 336, in send_message
    response = self._send_message_request(session, prepared_request)
               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/opt/venv3.11/lib/python3.11/site-packages/winrm/transport.py", line 346, in _send_message_request
    raise InvalidCredentialsError("the specified credentials were rejected by the server")
winrm.exceptions.InvalidCredentialsError: the specified credentials were rejected by the server

4. WinRM服务日志

PS C:\Windows\system32> Get-WinEvent -LogName "Microsoft-Windows-WinRM/Operational" -MaxEvents 1 | Format-List *

Message              : The authorization of the user failed with error 5
Id                   : 192
Version              : 0
Qualifiers           :
Level                : 4
Task                 : 8
Opcode               : 0
Keywords             : 4611686018427387916
RecordId             : 5435
ProviderName         : Microsoft-Windows-WinRM
ProviderId           : a7975c8f-ac13-49f1-87da-5a984a4ab417
LogName              : Microsoft-Windows-WinRM/Operational
ProcessId            : 3320
ThreadId             : 3744
MachineName          : winrm
UserId               : S-1-5-20
TimeCreated          : 4/8/2025 8:44:41 PM
ActivityId           : a3ddc236-a84c-0004-90ed-dda34ca8db01
RelatedActivityId

排查建议

核心问题定位

WinRM事件ID192错误5对应ERROR_ACCESS_DENIED,说明证书映射后的用户权限不足或映射规则不匹配。

具体排查步骤

  • 修正证书映射规则的Subject字段:
    WinRM证书映射中,Subject应填写客户端证书的主题名称(如CN=controller.example.com),而非证书指纹。当前配置将Subject设为客户端证书指纹,这是错误的。可在Ubuntu端执行openssl x509 -in "$cert_path" -noout -subject获取正确值,然后更新映射规则:
    winrm delete winrm/config/service/certmapping?Subject=50612F90702F2FEF1B777E987B7CD974DC99CE51
    winrm create winrm/config/service/certmapping '@{URI="*";Subject="CN=controller.example.com";Issuer="5A2F4E63BEBEDB186ED84BF722B54207E6664469";UserName="Administrator";Enabled="true"}'
    
  • 验证管理员WinRM权限:
    检查映射的Administrator用户是否具备WinRM远程访问权限:
    Get-PSSessionConfiguration -Name Microsoft.PowerShell | Select-Object Permission
    
    确保Builtin\Administrators组拥有FullControl权限,若缺失可执行:
    Set-PSSessionConfiguration -Name Microsoft.PowerShell -ShowSecurityDescriptorUI
    
  • 调整CA证书存储位置:
    WinRM服务运行在本地系统账户下,需将CA证书导入LocalMachine\Root存储,而非CurrentUser\Root:
    Import-Certificate -FilePath "C:\path\to\ca.crt" -CertStoreLocation "Cert:\LocalMachine\Root"
    
  • 适配FIPS模式加密要求:
    Ubuntu处于FIPS模式,需确保客户端证书使用FIPS合规算法(如SHA256)。重新生成SHA256指纹并更新映射规则:
    # Ubuntu端生成SHA256指纹
    thumbprint=$(openssl x509 -in "$cert_path" -noout -fingerprint -sha256 | sed 's/://g' | awk -F= '{print $2}')
    
  • 确认WinRM HTTPS监听证书有效性:
    检查WinRM绑定的证书(指纹13F3C1844B7617270D1331BEB02AD347FAB74D9C)是否在LocalMachine\My存储中,且证书的Subject或SAN包含winrm.example.com。

内容的提问来源于stack exchange,提问作者shachar0n

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 11:50:56