Ansible WinRM NTLM认证执行PowerShell脚本遇Socket连接错误求助
WinRM NTLM认证下执行Get-ADUser脚本出现Socket连接错误
主机配置
用于同步AD信息的服务器主机文件配置如下:
[Windows] 10.15.200.130 [Windows:vars] ansible_user=domainname\username ansible_password=passkey ansible_connection=winrm ansible_port=5985 ansible_winrm_transport=ntlm ansible_winrm_server_cert_validation=ignore ansible_winrm_kerberos_delegation=true
Ansible任务脚本
Playbook中执行的PowerShell任务:
- name: Run script win_powershell: script: | $results = Get-ADUser -Filter "SamAccountName -eq 'Jay.W'" -Properties Created,MemberOf,DistinguishedName | Select Name,SamAccountName,Enabled,Created,DistinguishedName,MemberOf $results | Format-Table -AutoSize | Out-File -FilePath C:\Users.txt -Width 5000 error_action: stop
错误信息
执行任务时返回如下错误:
fatal: [10.15.200.130]: FAILED! => { "changed": true, "debug": [], "error": [ { "category_info": { "activity": "Get-ADUser", "category": "ResourceUnavailable", "category_id": 21, "reason": "ADServerDownException", "target_name": "", "target_type": "" }, "error_details": null, "exception": { "help_link": null, "hresult": -2146233088, "inner_exception": { "help_link": null, "hresult": -2146233087, "inner_exception": { "help_link": null, "hresult": -2146232800, "inner_exception": { "help_link": null, "hresult": -2146233087, "inner_exception": { "help_link": null, "hresult": -2147467259, "inner_exception": null, "message": "An existing connection was forcibly closed by the remote host", "source": "System", "type": "System.Net.Sockets.SocketException" }, "message": "The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '00:02:00'.", "source": "System.ServiceModel", "type": "System.ServiceModel.CommunicationException" }, "message": "The write operation failed, see inner exception.", "source": "System", "type": "System.IO.IOException" }, "message": "The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '00:02:00'.", "source": "mscorlib", "type": "System.ServiceModel.CommunicationException" }, "message": "Unable to contact the server. This may be because this server does not exist, it is currently down, or it does not have the Active Directory Web Services running.", "source": "Microsoft.ActiveDirectory.Management", "type": "Microsoft.ActiveDirectory.Management.ADServerDownException" }, "fully_qualified_error_id": "ActiveDirectoryServer:0,Microsoft.ActiveDirectory.Management.Commands.GetADUser", "output": "Get-ADUser : Unable to contact the server. This may be because this server does not exist, it is currently down, or it \r\ndoes not have the Active Directory Web Services running.\r\nAt line:7 char:12\r\n+ $results = Get-ADUser -Filter \"SamAccountName -eq 'abby.t'\" -Properti ...\r\n+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\r\n + CategoryInfo : ResourceUnavailable: (:) [Get-ADUser], ADServerDownException\r\n + FullyQualifiedErrorId : ActiveDirectoryServer:0,Microsoft.ActiveDirectory.Management.Commands.GetADUser\r\n \r\n", "pipeline_iteration_info": [ 0, 0, 0 ], }
补充信息
- 直接在目标服务器的PowerShell中运行相同的
Get-ADUser命令可正常获取结果; - 10.15.200.130是AD副本服务器,操作会同步至主AD服务器;
- 使用Ansible的
community.windows.win_domain_user模块可正常创建AD用户,但ansible.windows.win_powershell模块执行脚本时出现Socket连接错误。
解决方案
1. 在Get-ADUser命令中明确指定AD服务器
WinRM会话下的PowerShell可能无法自动解析AD服务器,直接指定目标副本服务器地址:
- name: Run script with specified AD server win_powershell: script: | $results = Get-ADUser -Filter "SamAccountName -eq 'Jay.W'" -Server "10.15.200.130" -Properties Created,MemberOf,DistinguishedName | Select Name,SamAccountName,Enabled,Created,DistinguishedName,MemberOf $results | Format-Table -AutoSize | Out-File -FilePath C:\Users.txt -Width 5000 error_action: stop
2. 调整WinRM认证方式为CredSSP
NTLM认证不支持Kerberos委派,ansible_winrm_kerberos_delegation=true仅对Kerberos生效。改用CredSSP认证(需提前在目标服务器启用CredSSP):
修改主机配置中的认证参数:
ansible_winrm_transport=credssp ansible_winrm_kerberos_delegation=false
3. 检查WinRM会话权限与ADWS配置
- 确保Ansible使用的域用户拥有访问AD Web Services(ADWS)的权限;
- 在目标服务器上重启ADWS服务:
Restart-Service ADWS; - 检查防火墙规则,确保5985(WinRM HTTP端口)和9389(ADWS默认端口)正常开放。
内容的提问来源于stack exchange,提问作者Whaily
相关产品推荐
相关产品推荐

