能否在Linux上安装WinRM以实现跨平台PowerShell远程执行?
我希望从Windows通过Invoke-Command在Linux上运行脚本,已经安装PowerShell 7,执行以下脚本:
Invoke-Command -ComputerName $session -ScriptBlock { Write-Host "Hi" }
收到错误:
OpenError: [X] Connecting to the remote server X failed with the following error message: WinRM cannot process the request. The following error occurred while using Kerberos authentication: Cannot find the computer X. Verify that the computer exists on the network and that the name provided is spelled correctly. For more information, see the about_Remote_Troubleshooting Help topic.
想知道是否可以在Linux上安装或配置WinRM,目前仅找到Python包PyWinRM,未找到相关配置方法,请问这是否可行?
完全可以在Linux上配置WinRM服务端实现Windows远程调用,PyWinRM只是WinRM客户端工具(用于Python程序连接WinRM服务),你需要的是在Linux上部署WinRM服务端,具体步骤如下:
1. 在Linux端部署WinRM服务端
微软官方支持在Linux上通过PowerShell 7配置WinRM,步骤如下:
- 先在Linux上安装PowerShell 7:
- Debian/Ubuntu:
sudo apt update && sudo apt install powershell - RHEL/CentOS:
sudo dnf install powershell
- Debian/Ubuntu:
- 启动PowerShell:
pwsh - 执行命令启用WinRM:
这个命令会自动完成:创建WinRM服务配置、开放防火墙端口(默认5985/http、5986/https)、设置WinRM监听规则。Enable-PSRemoting -SkipNetworkProfileCheck
2. 解决Kerberos认证错误
你遇到的错误是因为Linux未加入Windows域,Kerberos认证无法生效,需要调整WinRM的认证方式,推荐启用基本认证+HTTPS(避免明文传输):
- 在Linux的PowerShell中执行:
# 启用基本认证 Set-Item WSMan:\localhost\Service\Auth\Basic -Value $true # 生成自签名证书(用于HTTPS加密) $cert = New-SelfSignedCertificate -DnsName "你的Linux机器IP或域名" -CertStoreLocation "cert:/LocalMachine/My" # 绑定证书到WinRM的HTTPS端口 New-Item -Path WSMan:\localhost\Listener -Transport HTTPS -Address * -CertificateThumbPrint $cert.Thumbprint -Force
3. 在Windows端调整连接命令
现在从Windows的PowerShell 7连接时,需要指定认证方式、启用SSL并指定HTTPS端口:
# 获取Linux机器的账号密码 $cred = Get-Credential -Message "输入Linux机器的用户名和密码" # 远程执行脚本 Invoke-Command -ComputerName "你的Linux机器IP或域名" -Credential $cred -ScriptBlock { Write-Host "Hi" } -UseSSL -Port 5986
关于PyWinRM
PyWinRM是Python生态下的WinRM客户端,只能用来从Python代码发起WinRM请求,不能作为Linux上的WinRM服务端使用,所以你需要的是上面提到的PowerShell 7配置方法来部署服务端。
内容的提问来源于stack exchange,提问作者kolieyr42

