You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible对接Windows主机CredSSP认证失败问题求助

问题说明

我搭建Ansible服务器对接Windows主机,打算用CredSSP做身份验证。但清单配置用HTTP(端口5985)而非HTTPS时,跑ping模块测试连通性就报错:

credssp: Server did not response with a CredSSP token after step TLS Handshake - actual 'Negotiate, Kerberos, Basic realm="WSMAN", CredSSP'

基础认证(Basic)能正常用,但CredSSP就是失败。当前清单配置如下:

[win]
host-IP-here

[win:vars]
ansible_user=my@domain.com
ansible_password=MyPasswordhere
ansible_connection=winrm
ansible_port=5985
ansible_winrm_transport=credssp
ansible_winrm_server_cert_validation=ignore
解决办法

1. 检查Windows主机的CredSSP配置

CredSSP要求Windows主机开启对应服务和配置,直接在Windows主机上运行这些PowerShell命令:

# 启用CredSSP服务器端配置
Enable-WSManCredSSP -Role Server -Force
# 确保WinRM服务处于启动状态
Start-Service WinRM
# 检查WinRM是否监听HTTP 5985端口
winrm enumerate winrm/config/listener

执行后要确认输出里包含Transport=http的监听项,且CredSSP已被启用。

2. 补全Ansible控制节点的CredSSP依赖

控制节点必须安装CredSSP相关的依赖包:

  • Debian/Ubuntu系统:
sudo apt install python3-winrm python3-winrm[credssp]
  • RHEL/CentOS系统:
sudo yum install python3-winrm python3-winrm-credssp

3. 调整WinRM的认证设置

在Windows主机上,确保WinRM允许CredSSP认证:

winrm set winrm/config/service/auth '@{CredSSP="true"}'

同时确认基础认证处于开启状态(不影响现有功能,仅保证环境配置一致):

winrm set winrm/config/service/auth '@{Basic="true"}'

4. 测试网络连通性

先确认Ansible控制节点能正常访问Windows主机的5985端口,用nc或telnet测试:

nc -zv <host-IP-here> 5985

5. 调整清单参数(可选)

如果上述步骤都无效,试试在清单里添加参数强制指定认证优先级:

[win:vars]
# 保留原有参数,新增以下配置
ansible_winrm_auth_methods=credssp,basic

内容的提问来源于stack exchange,提问作者Abhishek Bose

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 11:38:14