带SSL的远程PowerShell连接报错:用户授权失败(错误5)
问题与解决方案
问题场景
- 客户端:已加入域的Windows Server 2012 R2服务器
- 目标端:未加入域、已应用CIS Level 1基准的Windows Server 2019服务器
- 已完成配置:按PowerShell远程HTTPS教程配置,双方证书指纹确认无误
- 执行脚本:
$Username = 'remoteServerName\remoteLocalAdminUser' $Password = 'remoteUserPassword' $pass = ConvertTo-SecureString -AsPlainText $Password -Force $Cred = New-Object System.Management.Automation.PSCredential -ArgumentList $Username,$pass Invoke-Command -ComputerName "remoteServerName" -useSSL -scriptblock {Get-Service} -Credential $Cred
- 客户端报错:
[remoteServerName] Connecting to remote server remoteServerName failed with the following error message : Access is denied. For more information, see the about_Remote_Troubleshooting Help topic.
- CategoryInfo : OpenError: (remoteServerName:String) [], PSRemotingTransportException
- FullyQualifiedErrorId : AccessDenied,PSSessionStateBroken
- 目标端WinRM操作日志(
%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-WinRM%4Operational.evtx)报错:The authorization of the user failed with error 5
排查与解决方案
1. 检查目标端本地管理员的WinRM权限
CIS Level 1基准可能限制了WinRM允许的用户组,在目标端执行以下命令确认权限配置:
Get-PSSessionConfiguration | Select-Object Name, Permission
若本地管理员组未在允许列表,通过以下命令添加权限:
Set-PSSessionConfiguration -Name Microsoft.PowerShell -ShowSecurityDescriptorUI
在弹出的安全设置窗口中,添加目标本地管理员用户/组,赋予Execute (Invoke)权限。
2. 禁用目标端UAC远程权限过滤
非域环境下,UAC默认会过滤本地管理员的远程权限,需修改注册表:
在目标端执行:
Set-ItemProperty -Path HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -Name LocalAccountTokenFilterPolicy -Value 1 -Type DWord
修改后重启WinRM服务:
Restart-Service WinRM
3. 启用目标端WinRM的NTLM身份验证
CIS基准可能禁用了非域环境常用的NTLM验证,检查当前配置:
Get-WSManInstance -ResourceURI winrm/config/service/auth -Enumerate
若NTLM显示为false,执行命令启用:
Set-Item -Path WSMan:\localhost\Service\Auth\NTLM -Value $true
4. 确认客户端信任目标端证书
将目标端WinRM证书导出为.cer文件,导入到客户端的本地计算机\受信任的根证书颁发机构存储中,然后测试HTTPS连接:
Test-WSMan -ComputerName remoteServerName -UseSSL
5. 检查目标端WinRM HTTPS防火墙规则
CIS基准可能严格限制端口,确认WinRM HTTPS默认端口(5986)已开放:
Get-NetFirewallRule -Name *WinRM-HTTPS*
若规则未启用,执行命令启用:
Enable-NetFirewallRule -Name WINRM-HTTPS-In-TCP
内容的提问来源于stack exchange,提问作者dazedandconfused
相关产品推荐
相关产品推荐

