You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WinRM双HTTPS监听器证书更新:兼容性监听器如何操作?

WinRM双HTTPS监听器配置与证书更新问题

现有配置

我在WinRM上配置了两个HTTPS监听器(其中一个为兼容性监听器),详情如下:

Listener
    Address = *
    Transport = HTTPS
    Port = 5986
    Hostname = <hostname here>
    Enabled = true
    URLPrefix = wsman
    CertificateThumbprint = <thumb here>
    ListeningOn = <not important>

Listener [Source="Compatibility"]
    Address = *
    Transport = HTTPS
    Port = 443
    Hostname = <hostname here>
    Enabled = true
    URLPrefix = wsman
    CertificateThumbprint = <thumb here>
    ListeningOn = <same as above not important>

我可正常更新端口5986监听器的证书,但更新端口443监听器时无法指定端口——因二者地址与传输协议相同,无法定位目标监听器。

已尝试的无效操作

  • 执行命令出现「Invalid use of command line error」错误:
    winrm set winrm/config/Listener?Address=*+Transport=HTTPS+Port=443 @{CertificateThumbprint="<Thumbprint>"}
    
  • 以下命令无效(未删除旧监听器,需原地更新):
    winrm create winrm/config/Listener?Address=*+Transport=HTTPS '@{Hostname="<hostname>"; CertificateThumbprint="<Thumbprint>"; Port=443}'  
    
    winrm create winrm/config/Listener?Address=*+Transport=HTTPS '@{Hostname="<hostname>"; CertificateThumbprint="<Thumbprint>"; Port="443"}'
    
  • 使用监听器名称执行无报错,但Get-Item确认证书未更新:
    Set-Item WSMan:\localhost\Listener\Listener_874393735\CertificateThumbprint -Value <Thumbprint>
    
    Set-Item WSMan:\localhost\Listener\Listener_874393735\CertificateThumbprint -Value "<Thumbprint>" 
    
  • 执行命令出现错误:「This resource requires the following selectors: Address Transport」
    Set-WSManInstance -ResourceURI winrm/config/Listener -SelectorSet @{Address="*"; Transport="HTTPS";Port="443"} -ValueSet @{CertificateThumbprint=$certThumb}
    

咨询问题

  1. 配置两个HTTPS监听器是否为受支持的有效配置?
  2. 若是,如何更新兼容性监听器的证书?

解答

1. 双HTTPS监听器配置的有效性

是的,WinRM支持同时配置多个HTTPS监听器,只要它们的端口不同即可。这种配置属于官方认可的有效场景,比如你这里用标准端口5986搭配兼容性端口443的监听器,完全符合WinRM的设计规范。

2. 兼容性监听器的证书更新方法

标准WinRM命令行工具在区分同协议、同地址但不同端口的监听器时存在局限性,需要通过WSMan管理路径的唯一标识符精准定位目标监听器,具体步骤如下:

步骤1:获取兼容性监听器的唯一路径标识

打开PowerShell,执行命令列出所有WinRM监听器:

Get-ChildItem WSMan:\localhost\Listener

输出示例:

WSManConfig: Microsoft.WSMan.Management\WSMan::localhost\Listener

Name                      Type                    Keys
----                      ----                    ----
Listener_123456789        Container               {Address=*, Transport=HTTPS}
Listener_987654321        Container               {Address=*, Transport=HTTPS}

找到对应兼容性监听器的Name(比如Listener_987654321),可通过查看端口属性确认:

Get-Item WSMan:\localhost\Listener\Listener_987654321\Port

步骤2:更新证书并重启服务

使用唯一路径执行更新命令,之后必须重启WinRM服务让更改生效:

# 替换为你的监听器名称和新证书指纹
Set-Item WSMan:\localhost\Listener\Listener_987654321\CertificateThumbprint -Value "新证书指纹"
# 强制重启WinRM服务
Restart-Service WinRM -Force

验证更新结果

重启后执行以下命令确认证书指纹已更新:

Get-Item WSMan:\localhost\Listener\Listener_987654321\CertificateThumbprint

或通过winrm命令查看监听器详情:

winrm enumerate winrm/config/Listener

内容的提问来源于stack exchange,提问作者mrfreester

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 15:03:19