使用Jenkins在Windows服务器执行Chef命令时WinRM认证失败问题求助
I’ve run into this exact WinRM authorization error before when setting up Jenkins to interact with Windows servers, so let me walk you through the most effective fixes based on hands-on troubleshooting:
1. Correct the Username Format (Most Common Fix)
The error message calls this out directly, and it’s usually the root cause:
- Domain users: Prefix the username with your domain name using the format
domain_name\username, e.g.,CORP\demo-user - Local server users: Prefix with the target server’s computer name or IP address, e.g.,
WIN-SRV-01\demo-useror172.54.78.989\demo-user - Never use just
demo-user—WinRM will default to the Jenkins server’s local/domain context, which won’t match the target machine’s user account.
2. Verify WinRM Service Configuration on the Target Server
Log into the Windows server with admin rights, open PowerShell, and run these checks:
- Check enabled authentication methods:
Ensurewinrm get winrm/config/service/AuthBasicandNegotiateare set totrue. If not, enable them:winrm set winrm/config/service/auth @{Basic="true"} winrm set winrm/config/service/auth @{Negotiate="true"} - Confirm the WinRM service is running and set to auto-start:
Get-Service WinRM # If stopped, start it and set auto-start Start-Service WinRM Set-Service WinRM -StartupType Automatic
3. Ensure the User Has Proper Permissions
- Add the
demo-userto the Remote Management Users group on the target server (this grants default WinRM access rights). You can do this via Computer Management > Local Users and Groups > Groups, or with PowerShell:Add-LocalGroupMember -Group "Remote Management Users" -Member "demo-user" - If your Chef commands require admin privileges, make sure
demo-useris also in the Administrators group (or has the necessary elevated rights to run Chef operations).
4. Test WinRM Connection Outside Jenkins
Rule out Jenkins-specific issues by testing the connection directly from a PowerShell prompt (on your local machine or Jenkins server):
Test-WSMan 172.54.78.989 -Credential (Get-Credential)
Enter the correctly formatted username and password. If this test passes, the problem lies in your Jenkins configuration; if it fails, the error message will give you more specific clues (e.g., network restrictions, invalid credentials).
5. Double-Check Jenkins Configuration
- If you’re using a Jenkins plugin for WinRM (like the Windows Remote Management plugin), confirm the username field uses the correct prefixed format, and the password is entered correctly (watch for special characters that might need escaping, though most plugins handle this automatically).
- For the
Execute Windows batch commandstep, ensure the command is configured to run on the remote Windows server (not locally on Jenkins) and that the WinRM credentials are properly linked to the target machine.
内容的提问来源于stack exchange,提问作者Promise Preston

