如何配置非默认WinRM端口?组策略参数异常问题求解
问题背景
在Windows Server 2012和2016上执行命令修改WinRM监听端口为443:
Set-Item -Path WSMan:\localhost\listener\listener*\Port -Value 443
收到报错:
Set-Item : WS-Management does not allow changes to a listener created automatically by the group policy. The policy "Allow Auto Configuration of listeners on WinRm service" would need to be set to "Not Configured" in order to create a new listener for same Address and Transport or to modify an already existing listener.
但在组策略路径Computer Configuration -> Administrative Templates -> Windows Components -> Windows Remote Management(WinRM) -> WinRM Service下找不到名为“Allow Auto Configuration of listeners on WinRm service”的策略项。
解决步骤
1. 确认策略项的正确名称(版本适配)
Windows Server 2012/2016中,该策略项的中文名称为**“允许WinRM服务自动配置监听器”,英文版系统则保留原英文名称。如果本地组策略找不到,优先检查是否是域组策略**推送的配置——域环境下本地组策略会被域策略覆盖,需查看域控端的组策略设置。
2. 排查生效的组策略
执行以下命令生成组策略报告,定位影响WinRM监听器的配置来源:
gpresult /h gp_report.html
打开生成的gp_report.html,搜索“WinRM”相关条目,确认是否有域策略强制配置了监听器。若为域策略控制,需联系域管理员将对应策略调整为“未配置”。
3. 手动删除自动监听器并重新配置
若无法修改组策略,可直接删除组策略自动创建的监听器,再手动配置443端口的监听器:
- 查看当前所有WinRM监听器:
Get-ChildItem WSMan:\localhost\Listener
- 删除自动创建的监听器(替换
Listener_xxxxxx为实际监听器名称):
Remove-Item WSMan:\localhost\Listener\Listener_xxxxxx -Recurse
- 手动创建HTTPS监听器(需提前准备SSL证书,替换
你的证书指纹为实际证书指纹):
New-Item -Path WSMan:\localhost\Listener -Transport HTTPS -Address * -CertificateThumbprint "你的证书指纹" -Port 443
- 重启WinRM服务使配置生效:
Restart-Service WinRM
4. 验证配置结果
执行以下命令确认监听器端口已改为443:
Get-ChildItem WSMan:\localhost\Listener | Select-Object -ExpandProperty Keys
内容的提问来源于stack exchange,提问作者Meron

