You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible WinRM NTLM认证执行PowerShell脚本遇Socket连接错误求助

WinRM NTLM认证下执行Get-ADUser脚本出现Socket连接错误

主机配置

用于同步AD信息的服务器主机文件配置如下:

[Windows]
10.15.200.130

[Windows:vars]
ansible_user=domainname\username    
ansible_password=passkey
ansible_connection=winrm
ansible_port=5985
ansible_winrm_transport=ntlm
ansible_winrm_server_cert_validation=ignore
ansible_winrm_kerberos_delegation=true

Ansible任务脚本

Playbook中执行的PowerShell任务:

- name: Run script
  win_powershell: 
    script: |     
      $results = Get-ADUser -Filter "SamAccountName -eq 'Jay.W'" -Properties Created,MemberOf,DistinguishedName | Select Name,SamAccountName,Enabled,Created,DistinguishedName,MemberOf
      $results | Format-Table -AutoSize | Out-File -FilePath C:\Users.txt -Width 5000
    error_action: stop

错误信息

执行任务时返回如下错误:

fatal: [10.15.200.130]: FAILED! => {
"changed": true,
"debug": [],
"error": [
    {
        "category_info": {
            "activity": "Get-ADUser",
            "category": "ResourceUnavailable",
            "category_id": 21,
            "reason": "ADServerDownException",
            "target_name": "",
            "target_type": ""
        },
        "error_details": null,
        "exception": {
            "help_link": null,
            "hresult": -2146233088,
            "inner_exception": {
                "help_link": null,
                "hresult": -2146233087,
                "inner_exception": {
                    "help_link": null,
                    "hresult": -2146232800,
                    "inner_exception": {
                        "help_link": null,
                        "hresult": -2146233087,
                        "inner_exception": {
                            "help_link": null,
                            "hresult": -2147467259,
                            "inner_exception": null,
                            "message": "An existing connection was forcibly closed by the remote host",
                            "source": "System",
                            "type": "System.Net.Sockets.SocketException"
                        },
                        "message": "The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '00:02:00'.",
                        "source": "System.ServiceModel",
                        "type": "System.ServiceModel.CommunicationException"
                    },
                    "message": "The write operation failed, see inner exception.",
                    "source": "System",
                    "type": "System.IO.IOException"
                },
                "message": "The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '00:02:00'.",
                "source": "mscorlib",
                "type": "System.ServiceModel.CommunicationException"
            },
            "message": "Unable to contact the server. This may be because this server does not exist, it is currently down, or it does not have the Active Directory Web Services running.",
            "source": "Microsoft.ActiveDirectory.Management",
            "type": "Microsoft.ActiveDirectory.Management.ADServerDownException"
        },
        "fully_qualified_error_id": "ActiveDirectoryServer:0,Microsoft.ActiveDirectory.Management.Commands.GetADUser",
        "output": "Get-ADUser : Unable to contact the server. This may be because this server does not exist, it is currently down, or it \r\ndoes not have the Active Directory Web Services running.\r\nAt line:7 char:12\r\n+ $results = Get-ADUser -Filter \"SamAccountName -eq 'abby.t'\" -Properti ...\r\n+            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\r\n    + CategoryInfo          : ResourceUnavailable: (:) [Get-ADUser], ADServerDownException\r\n    + FullyQualifiedErrorId : ActiveDirectoryServer:0,Microsoft.ActiveDirectory.Management.Commands.GetADUser\r\n \r\n",
        "pipeline_iteration_info": [
            0,
            0,
            0
        ],
}

补充信息

  • 直接在目标服务器的PowerShell中运行相同的Get-ADUser命令可正常获取结果;
  • 10.15.200.130是AD副本服务器,操作会同步至主AD服务器;
  • 使用Ansible的community.windows.win_domain_user模块可正常创建AD用户,但ansible.windows.win_powershell模块执行脚本时出现Socket连接错误。

解决方案

1. 在Get-ADUser命令中明确指定AD服务器

WinRM会话下的PowerShell可能无法自动解析AD服务器,直接指定目标副本服务器地址:

- name: Run script with specified AD server
  win_powershell: 
    script: |     
      $results = Get-ADUser -Filter "SamAccountName -eq 'Jay.W'" -Server "10.15.200.130" -Properties Created,MemberOf,DistinguishedName | Select Name,SamAccountName,Enabled,Created,DistinguishedName,MemberOf
      $results | Format-Table -AutoSize | Out-File -FilePath C:\Users.txt -Width 5000
    error_action: stop

2. 调整WinRM认证方式为CredSSP

NTLM认证不支持Kerberos委派,ansible_winrm_kerberos_delegation=true仅对Kerberos生效。改用CredSSP认证(需提前在目标服务器启用CredSSP):
修改主机配置中的认证参数:

ansible_winrm_transport=credssp
ansible_winrm_kerberos_delegation=false

3. 检查WinRM会话权限与ADWS配置

  • 确保Ansible使用的域用户拥有访问AD Web Services(ADWS)的权限;
  • 在目标服务器上重启ADWS服务:Restart-Service ADWS;
  • 检查防火墙规则,确保5985(WinRM HTTP端口)和9389(ADWS默认端口)正常开放。

内容的提问来源于stack exchange,提问作者Whaily

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 23:24:55