You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows主机用Ansible become:true时遇Win32ErrorCode 1058错误求助

解决Ansible win_credential模块启用become:true时的Win32ErrorCode 1058错误

问题复现

使用Ansible Automation Platform在Windows主机上执行community.windows.win_credential模块时,启用become: true后触发如下错误:

{
  "exception": "Exception calling \"CreateProcessAsUser\" with \"9\" argument(s): \"CreateProcessWithTokenW() failed (The service cannot be started, either because it is disabled or because it has no enabled devices associated with it, Win32ErrorCode 1058)\"\r\nAt line:103 char:5\r\n+     $result = [Ansible.Become.BecomeUtil]::CreateProcessAsUser($usern ...\r\n+     ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\r\n    + CategoryInfo          : NotSpecified: (:) [], MethodInvocationException\r\n    + FullyQualifiedErrorId : Win32Exception\r\n\r\nScriptStackTrace:\r\nat <ScriptBlock>, <No file>: line 103\r\nat <ScriptBlock><End>, <No file>: line 137\r\nat <ScriptBlock>, <No file>: line 11\r\n\r\nSystem.Management.Automation.MethodInvocationException: Exception calling \"CreateProcessAsUser\" with \"9\" argument(s): \"CreateProcessWithTokenW() failed (The service cannot be started, either because it is disabled or because it has no enabled devices associated with it, Win32ErrorCode 1058)\" ---> Ansible.Process.Win32Exception: CreateProcessWithTokenW() failed (The service cannot be started, either because it is disabled or because it has no enabled devices associated with it, Win32ErrorCode 1058)\r\n   at Ansible.Become.BecomeUtil.CreateProcessAsUser(String username, String password, LogonFlags logonFlags, LogonType logonType, String lpApplicationName, String lpCommandLine, String lpCurrentDirectory, IDictionary environment, Byte[] stdin) in c:\\Users\\myUser\\AppData\\Local\\Temp\\rwchbapb.1.cs:line 309\r\n   at CallSite.Target(Closure , CallSite , Type , Object , Object , Object , Object , Object , Object , Object , Object , Object )\r\n   --- End of inner exception stack trace ---\r\n   at System.Management.Automation.ExceptionHandlingOps.CheckActionPreference(FunctionContext funcContext, Exception exception)\r\n   at System.Management.Automation.Interpreter.ActionCallInstruction`2.Run(InterpretedFrame frame)\r\n   at System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame)\r\n   at System.Management.Automation.Interpreter.EnterTryCatchFinallyInstruction.Run(InterpretedFrame frame)",
  "msg": "internal error: failed to become user 'myUser': Exception calling \"CreateProcessAsUser\" with \"9\" argument(s): \"CreateProcessWithTokenW() failed (The service cannot be started, either because it is disabled or because it has no enabled devices associated with it, Win32ErrorCode 1058)\"",
  "_ansible_no_log": false,
  "changed": false
}

禁用become则会触发提示:Failed to access the user's credential store, run the module with become.

已知条件:

  • 目标用户属于本地Administrators组
  • 已配置runas提权方法、用户名和密码,且与登录主机的账号一致
  • 已尝试相关排查步骤但无效

解决方案

1. 启用并运行Secondary Logon服务

Win32ErrorCode 1058直接指向Secondary Logon服务未启用/运行,Ansible的runas提权依赖该服务创建用户上下文进程:

  • 打开Windows服务管理器(运行services.msc)
  • 找到Secondary Logon服务,设置启动类型为自动
  • 启动该服务,确保状态为正在运行

2. 调整Ansible become_flags参数

添加logon_type=new_credentials参数,修改runas的登录类型,避免交互式会话依赖:

- name: 管理Windows凭据
  hosts: windows_hosts
  become: true
  become_method: runas
  become_flags: logon_type=new_credentials
  tasks:
    - name: 添加目标凭据
      community.windows.win_credential:
        name: "target_service"
        type: generic
        username: "local_admin"
        secret: "secure_password"
        state: present

3. 验证权限与账号配置

  • 避免使用与Ansible登录主机相同的账号执行become操作,改用另一个本地管理员账号测试(同账号会话可能引发冲突)
  • 确认目标账号拥有允许本地登录和允许通过远程桌面服务登录权限(组策略路径:计算机配置 > Windows设置 > 安全设置 > 本地策略 > 用户权限分配)

4. 排查组策略限制

检查是否有组策略禁用了Secondary Logon服务,或者限制了用户的登录方式:

  • 运行gpedit.msc打开本地组策略编辑器
  • 检查计算机配置 > 管理模板 > 系统 > 服务下是否有禁用Secondary Logon的策略
  • 确认用户权限分配中的相关权限未被限制

内容的提问来源于stack exchange,提问作者jeremywat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 08:08:31