Ansible 2.9.18部署完成后调用mail模块发送邮件通知时返回403错误的排查求助
Let's break down why you're hitting that ntlm: Bad HTTP response returned from server. Code 403 error, especially since other tasks on the same server work fine. Here are the most likely causes and fixes to try:
1. NTLM Authentication Mismatches
The error explicitly calls out NTLM, so this is the first place to check:
- Incorrect credentials: Double-check the
usernameandpasswordin your mail module config. Even if other tasks use valid credentials, your mail server might require a different set (like a dedicated service account for automated emails). Watch out for special characters in passwords that need YAML escaping—wrap them in single quotes if needed. - NTLM version incompatibility: Your mail server might require NTLMv2, but older Ansible versions (like 2.9.18) might default to NTLMv1. Try adding
auth_type: ntlmv2to your mail module parameters to force the newer version.
2. Mail Server IP/Access Restrictions
Just because your server can run other tasks doesn't mean it's allowed to send emails via your mail server:
- Check if your server's IP is on the mail server's whitelist for authenticated SMTP/NTLM access. Many enterprise mail servers (like Exchange) restrict which IPs can send automated emails to prevent abuse.
- Verify that the mail server's firewall isn't blocking incoming connections from your server on the SMTP port (usually 587 for TLS, 25 for unencrypted, or 465 for SSL).
3. Proxy Configuration Conflicts
You mentioned installing proxy programs—this could be interfering with the mail module's requests:
- Other tasks might be configured to use the proxy correctly, but the mail module might pick up incorrect proxy settings from environment variables. Try explicitly disabling the proxy in the mail module with
proxy: ""to rule this out. - If your proxy requires authentication, make sure the mail module has the correct proxy credentials (use
proxy_usernameandproxy_passwordparameters if needed).
4. Mail Server Permissions/Endpoint Requirements
Some mail servers (especially Microsoft Exchange) have strict rules for automated clients:
- Ensure the service account you're using for the mail module has the "Send As" or "Send On Behalf Of" permission enabled in the mail server admin console.
- Confirm that your mail server allows client applications to send emails via the SMTP endpoint you're using. Some servers require enabling specific protocols or APIs for automated tools.
5. Outdated Ansible Module Limitations
Ansible 2.9.18 is a fairly old release (released in 2021), and the mail module had several NTLM-related fixes in later versions. If none of the above steps work, consider upgrading to a newer stable Ansible version (like 2.12 or later) to see if the bug is already resolved.
Quick Test Playbook
Here's a minimal playbook to test your mail module config with the suggested fixes:
- name: Test NTLM mail authentication hosts: localhost tasks: - name: Send test email mail: host: your-mail-server.example.com port: 587 username: "your-service-account@example.com" password: 'your-secure-password' auth_type: ntlmv2 proxy: "" to: your-test-email@example.com subject: Ansible Test Mail body: This is a test to troubleshoot the 403 NTLM error.
内容的提问来源于stack exchange,提问作者Mani

