You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu下Node.js应用用Kerberos连接域内Windows机器遇401错误求助

问题:Node.js TypeScript应用通过Kerberos连接域内Windows机器报401错误

在Ubuntu系统上运行Node.js TypeScript应用,需连接域内远程Windows机器。最初尝试WinRM基本认证不符合要求,遂安装npm的kerberos包,在Ubuntu中配置krb5.conf文件并成功生成TGT票据。但通过Node.js借助Kerberos连接时,始终出现HTTP/1.1 401错误,报错信息为:gss_init_sec_context() failed: Message stream modified。

已确认主机、域、用户名、密码、主体及服务信息均正确,期望建立连接后能在Node.js应用中执行多条命令并读取输出,但连接错误始终存在。

以下是应用中使用Kerberos的代码片段:

const kerberos = require('kerberos');
const { exec } = require('child_process');
const { v5: uuidv5 } = require('uuid');

async CreateShell_kerberos(config: any) {
    const {host} = config;
    const port = config.port;
    const username = config.username;
    const password = config.password;
    const domain = config.domainName;
    const principal = `${username}@${domain}`;
    const url = `https://${host}.${domain}:${port}/wsman`;
    const uuid = uuidv5.URL;
    const authOptions = {
        principal: principal,
        keytab: null,
        password: password,
    };

    const service = `HTTP@${host}.${domain}`;
    const searchTicket =` ${host}.${domain}`;
    const ticketPassed = await this.winrmKerberosService.checkKerberosTicket(principal, password, searchTicket);

    if (ticketPassed) {
        const createShellRequest = `
        <s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:wsa="http://schemas.xmlsoap.org/ws/2004/08/addressing" xmlns:wsman="http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd"> 
            <s:Header> 
                <wsa:Action>http://schemas.xmlsoap.org/ws/2004/09/transfer/Create</wsa:Action> 
                <wsa:To>${url}</wsa:To> 
                <wsa:MessageID>uuid:${uuid}</wsa:MessageID> 
                <wsa:ReplyTo> 
                    <wsa:Address>http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</wsa:Address> 
                </wsa:ReplyTo> 
            </s:Header> 
            <s:Body> 
                <rsp:Shell xmlns:rsp="http://schemas.microsoft.com/wbem/wsman/1/windows/shell"> 
                    <rsp:InputStreams>stdin</rsp:InputStreams> 
                    <rsp:OutputStreams>stdout stderr</rsp:OutputStreams> 
                </rsp:Shell> 
            </s:Body> 
        </s:Envelope>`;

        kerberos.initializeClient(service, authOptions, (err, client) => {
            if (err) {
                console.error('Kerberos initialization error:', err);
                return;
            }                
            client.step('', async (err, kerberosResponse) => {
                if (err) {
                    console.error('Kerberos authentication error:', err);
                    return;
                }
                console.log(client)
                const curlCommand = `curl -k --negotiate -u : -X POST "${url}" -H "Content-Type: application/soap+xml" -d '${createShellRequest}'`;
                this.executeCommand(curlCommand, this.executeCommandDomain(client, config));                  
            });
        });
    }        
}

async executeCommand(command, callback) {
    exec(command, (error, stdout, stderr) => {
        if (error) {
            console.error(`Error: ${error.message}`);
            return;
        }
        if (stderr) {
            console.error(`Stderr: ${stderr}`);
            return;
        }
        callback(stdout);
    });
}

async executeCommandDomain(client, config) {        
    // Command 1
    const command1 = 'echo Hello, World!';
    this.executeCommand(command1, (output1) => {
        console.log('Output of command 1:', output1);
    });
}

内容的提问来源于stack exchange,提问作者Daoud El Gharib

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 19:55:10