You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Rundeck配置Windows节点失败:WinRM 401认证错误求助

Rundeck连接Windows节点WinRM 401错误排查与解决

报错信息

[overthere-winrm:172.16.58.78] failed: WinRM Error:
Unexpected HTTP response on http://172.16.58.78:5985/wsman: (401)
Failed: WinRMProtocolError:WinRM Error: 
Unexpected HTTP response on http://172.16.58.78:5985/wsman: (401)

Rundeck节点配置

_myNewNode:
  description: "_myNewNode"
  tags: "windows"
  hostname: "_myIp"
  osArch: "amd64"
  osFamily: "windows"
  node-executor: "overthere-winrm"
  winrm-auth-type: "basic"
  winrm-cmd: "CMD"
  winrm-protocol: "http"
  username: "_myUsername"
  winrm-password-storage-path: "keys/_myPassword"

目标节点WinRM配置

PS C:\Windows\system32> winrm get winrm/config
Config
    MaxEnvelopeSizekb = 500
    MaxTimeoutms = 60000
    MaxBatchItems = 32000
    MaxProviderRequests = 4294967295
    Client
        NetworkDelayms = 5000
        URLPrefix = wsman
        AllowUnencrypted = true
        Auth
            Basic = true
            Digest = true
            Kerberos = false
            Negotiate = true
            Certificate = true
            CredSSP = false
        DefaultPorts
            HTTP = 5985
            HTTPS = 5986
        TrustedHosts = *
    Service
        RootSDDL = O:NSG:BAD:P(A;;GA;;;BA)(A;;GR;;;IU)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)
        MaxConcurrentOperations = 4294967295
        MaxConcurrentOperationsPerUser = 1500
        EnumerationTimeoutms = 240000
        MaxConnections = 300
        MaxPacketRetrievalTimeSeconds = 120
        AllowUnencrypted = true
        Auth
            Basic = true
            Kerberos = true
            Negotiate = true
            Certificate = false
            CredSSP = true
            CbtHardeningLevel = Relaxed
        DefaultPorts
            HTTP = 5985
            HTTPS = 5986
        IPv4Filter = *
        IPv6Filter = *
        EnableCompatibilityHttpListener = false
        EnableCompatibilityHttpsListener = false
        CertificateThumbprint
        AllowRemoteAccess = true
    Winrs
        AllowRemoteShellAccess = true
        IdleTimeout = 7200000
        MaxConcurrentUsers = 2147483647
        MaxShellRunTime = 2147483647
        MaxProcessesPerShell = 2147483647
        MaxMemoryPerShellMB = 2147483647
        MaxShellsPerUser = 2147483647

连通性验证

已确认Rundeck服务器可连通目标节点5985端口:

Poroto Local Address          Foreign Address        State
TCP    0.0.0.0:5985           0.0.0.0:0              LISTENING

排查与解决步骤

  1. 验证账号密码有效性
    确认_myUsername和keys/_myPassword存储的密码完全正确,包括大小写、特殊字符。可直接在目标节点本地用该账号登录,排除密码错误问题。

  2. 检查账号权限

    • 用于WinRM的账号需具备本地管理员权限,或至少加入Remote Management Users组:
      net localgroup "Remote Management Users" "_myUsername" /add
      
    • 检查本地安全策略:本地策略 -> 用户权限分配 -> 允许通过远程桌面服务登录中需包含该账号。
  3. 确认WinRM基础配置生效
    重新执行以下命令确保Basic认证和非加密传输开启,之后重启WinRM服务:

    winrm set winrm/config/service/auth @{Basic="true"}
    winrm set winrm/config/service @{AllowUnencrypted="true"}
    Restart-Service WinRM
    
  4. 排查密码存储问题
    临时将Rundeck节点配置中的密码改为明文(仅测试用),替换winrm-password-storage-path为password: "明文密码",验证是否能连接,排除存储路径或加密配置错误。

  5. 关闭UAC远程限制
    Windows默认限制本地管理员远程执行高权限操作,需修改注册表:

    • 定位到HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
    • 创建或修改DWORD值LocalAccountTokenFilterPolicy,设置为1
    • 重启目标节点生效
  6. 切换认证方式测试
    如果Basic认证持续失败,尝试切换为Negotiate认证,修改Rundeck节点配置:

    winrm-auth-type: "negotiate"
    

内容的提问来源于stack exchange,提问作者Haze

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 19:00:34