You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求协助:Ansible证书认证WinRM连接失败问题排查

证书认证WinRM连接Ansible失败排查请求

我正在尝试通过证书认证配置Ansible与Windows主机的安全WinRM连接,已参考多篇教程完成配置,但执行ansible web -m win_ping -vvv测试时失败,报错信息如下:

[server ip address] | UNREACHABLE! => {
    "changed": false,
    "msg": "certificate: the specified credentials were rejected by the server",
    "unreachable": true
}

使用nc -vz [ip-address] 5986验证后,确认5986端口可正常连通。

相关配置信息

WinRM监听器配置

winrm e winrm/config/Listener

Listener
    Address = *
    Transport = HTTP
    Port = 5985
    Hostname
    Enabled = true
    URLPrefix = wsman
    CertificateThumbprint
    ListeningOn = 127.0.0.1, 128.149.127.170, ::1, fe80::f94:6d4a:dffe:aa66%12

Listener
    Address = *
    Transport = HTTPS
    Port = 5986
    Hostname = [hostname]
    Enabled = true
    URLPrefix = wsman
    CertificateThumbprint = E80477462AD9398D6859FE9070693334BCEFBBD6
    ListeningOn = 127.0.0.1, 128.149.127.170, ::1, fe80::f94:6d4a:dffe:aa66%12

WinRM认证配置

winrm get winrm/config/client/auth
Auth
    Basic = false [Source="GPO"]
    Digest = false [Source="GPO"]
    Kerberos = false
    Negotiate = true
    Certificate = true
    CredSSP = false

PS C:\> winrm get winrm/config/service/auth
Auth
    Basic = false [Source="GPO"]
    Kerberos = true
    Negotiate = true
    Certificate = true
    CredSSP = true
    CbtHardeningLevel = Relaxed

Ansible主机文件配置

[web]
[server ip address]

[web:vars]
ansible_user=[user]
ansible_password=[password]
ansible_connection=winrm
ansible_winrm_transport=certificate
ansible_winrm_cert_pem=/home/user/.ssh/client_cert.pem
ansible_winrm_cert_key_pem=/home/user/.ssh/client_key.pem
ansible_port=5986
ansible_winrm_scheme=https
ansible_winrm_server_cert_validation=ignore

已确认所使用用户为Windows服务器本地管理员,请求协助排查该问题。


排查建议

  • 检查客户端证书是否已导入Windows主机的本地计算机\个人证书存储,且证书的**使用者名称(CN)或使用者备用名称(SAN)**需与Ansible配置的ansible_user匹配,或者已通过winrm set winrm/config/service/certmapping将证书绑定到目标用户账户
  • 确认客户端证书私钥未设置密码;如果私钥有密码,需在Ansible主机配置中添加ansible_winrm_cert_key_passphrase=[私钥密码]变量
  • 验证WinRM服务证书认证的实际生效状态:尽管当前配置显示Certificate = true,但GPO可能存在覆盖,可重新执行winrm set winrm/config/service/auth @{Certificate="true"}确保设置生效
  • 检查客户端证书的有效性:确认证书未过期、密钥用法包含**客户端认证(Client Authentication)**扩展(可通过Windows证书管理器或openssl x509 -in client_cert.pem -text -noout查看)
  • 查看Windows事件日志:在事件查看器中定位到应用程序和服务日志\Microsoft\Windows\WinRM\Operational,查找ID为16384或相关认证失败的日志条目,获取更具体的拒绝原因

内容的提问来源于stack exchange,提问作者eia92

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 05:40:46