Windows主机用Ansible become:true时遇Win32ErrorCode 1058错误求助
解决Ansible win_credential模块启用become:true时的Win32ErrorCode 1058错误
问题复现
使用Ansible Automation Platform在Windows主机上执行community.windows.win_credential模块时,启用become: true后触发如下错误:
{ "exception": "Exception calling \"CreateProcessAsUser\" with \"9\" argument(s): \"CreateProcessWithTokenW() failed (The service cannot be started, either because it is disabled or because it has no enabled devices associated with it, Win32ErrorCode 1058)\"\r\nAt line:103 char:5\r\n+ $result = [Ansible.Become.BecomeUtil]::CreateProcessAsUser($usern ...\r\n+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\r\n + CategoryInfo : NotSpecified: (:) [], MethodInvocationException\r\n + FullyQualifiedErrorId : Win32Exception\r\n\r\nScriptStackTrace:\r\nat <ScriptBlock>, <No file>: line 103\r\nat <ScriptBlock><End>, <No file>: line 137\r\nat <ScriptBlock>, <No file>: line 11\r\n\r\nSystem.Management.Automation.MethodInvocationException: Exception calling \"CreateProcessAsUser\" with \"9\" argument(s): \"CreateProcessWithTokenW() failed (The service cannot be started, either because it is disabled or because it has no enabled devices associated with it, Win32ErrorCode 1058)\" ---> Ansible.Process.Win32Exception: CreateProcessWithTokenW() failed (The service cannot be started, either because it is disabled or because it has no enabled devices associated with it, Win32ErrorCode 1058)\r\n at Ansible.Become.BecomeUtil.CreateProcessAsUser(String username, String password, LogonFlags logonFlags, LogonType logonType, String lpApplicationName, String lpCommandLine, String lpCurrentDirectory, IDictionary environment, Byte[] stdin) in c:\\Users\\myUser\\AppData\\Local\\Temp\\rwchbapb.1.cs:line 309\r\n at CallSite.Target(Closure , CallSite , Type , Object , Object , Object , Object , Object , Object , Object , Object , Object )\r\n --- End of inner exception stack trace ---\r\n at System.Management.Automation.ExceptionHandlingOps.CheckActionPreference(FunctionContext funcContext, Exception exception)\r\n at System.Management.Automation.Interpreter.ActionCallInstruction`2.Run(InterpretedFrame frame)\r\n at System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame)\r\n at System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame)", "msg": "internal error: failed to become user 'myUser': Exception calling \"CreateProcessAsUser\" with \"9\" argument(s): \"CreateProcessWithTokenW() failed (The service cannot be started, either because it is disabled or because it has no enabled devices associated with it, Win32ErrorCode 1058)\"", "_ansible_no_log": false, "changed": false }
禁用become则会触发提示:Failed to access the user's credential store, run the module with become.
已知条件:
- 目标用户属于本地Administrators组
- 已配置runas提权方法、用户名和密码,且与登录主机的账号一致
- 已尝试相关排查步骤但无效
解决方案
1. 启用并运行Secondary Logon服务
Win32ErrorCode 1058直接指向Secondary Logon服务未启用/运行,Ansible的runas提权依赖该服务创建用户上下文进程:
- 打开Windows服务管理器(运行
services.msc) - 找到
Secondary Logon服务,设置启动类型为自动 - 启动该服务,确保状态为正在运行
2. 调整Ansible become_flags参数
添加logon_type=new_credentials参数,修改runas的登录类型,避免交互式会话依赖:
- name: 管理Windows凭据 hosts: windows_hosts become: true become_method: runas become_flags: logon_type=new_credentials tasks: - name: 添加目标凭据 community.windows.win_credential: name: "target_service" type: generic username: "local_admin" secret: "secure_password" state: present
3. 验证权限与账号配置
- 避免使用与Ansible登录主机相同的账号执行become操作,改用另一个本地管理员账号测试(同账号会话可能引发冲突)
- 确认目标账号拥有允许本地登录和允许通过远程桌面服务登录权限(组策略路径:计算机配置 > Windows设置 > 安全设置 > 本地策略 > 用户权限分配)
4. 排查组策略限制
检查是否有组策略禁用了Secondary Logon服务,或者限制了用户的登录方式:
- 运行
gpedit.msc打开本地组策略编辑器 - 检查计算机配置 > 管理模板 > 系统 > 服务下是否有禁用Secondary Logon的策略
- 确认用户权限分配中的相关权限未被限制
内容的提问来源于stack exchange,提问作者jeremywat
相关产品推荐
相关产品推荐

