You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WinRM客户端请求处理失败排查及远程启用PSRemoting可行性咨询

问题背景

我尝试运行以下命令:

Invoke-Command 10.xx.3x.1xx -ScriptBlock {Get-ADDefaultDomainPasswordPolicy}

但出现错误:

OpenError: [10.xx.3x.1xx] 连接远程服务器10.xx.3x.1xx失败,错误信息如下:The WinRM client cannot process the request. 使用IP地址进行默认认证需满足以下条件:传输协议为HTTPS,或目标主机在TrustedHosts列表中且提供明确凭据。请使用winrm.cmd配置TrustedHosts。注意TrustedHosts列表中的计算机可能未经过身份验证。如需了解设置TrustedHosts的更多信息,请运行命令:winrm help config。更多信息请查看about_Remote_Troubleshooting帮助主题。

这些主机均在域内,且与域内另一主机通信正常。我从发起命令的远程机器执行Test-WsMan host_ip命令,返回结果如下:

wsmid : http://schemas.dmtf.org/wbem/wsman/identity/1/wsmanidentity.xsd
ProtocolVersion : http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd
ProductVendor : Microsoft Corporation
ProductVersion : OS: 0.0.0 SP: 0.0 Stack: 3.0

我还在远程主机重新执行了Enable-PSRemoting(执行后无返回信息),但仍出现上述错误。

现咨询两个问题:

  1. 最关注的问题:如何解决当前报错?
  2. 能否远程启用未允许PS远程执行的主机,待命令执行成功后恢复其原状态?

问题解答

1. 解决当前报错的方法

根据错误提示,核心原因是使用IP地址进行WinRM远程连接时的认证限制,结合域环境,有两种直接可行的方案:

方案一:使用主机名而非IP地址连接

域环境下优先使用目标主机的完全限定域名(FQDN)或NetBIOS名,可直接利用Kerberos认证,无需额外配置TrustedHosts:

# 使用完全限定域名
Invoke-Command -ComputerName "目标主机名.域名后缀" -ScriptBlock {Get-ADDefaultDomainPasswordPolicy}
# 或使用NetBIOS名
Invoke-Command -ComputerName "目标主机名" -ScriptBlock {Get-ADDefaultDomainPasswordPolicy}

方案二:配置TrustedHosts并提供明确凭据

如果必须使用IP地址连接,按以下步骤操作:

  • 第一步:在发起命令的本地机器上,将目标IP添加到TrustedHosts列表
    # 添加单个IP(-Concatenate参数保留原有列表内容)
    Set-Item WSMan:\localhost\Client\TrustedHosts -Value "10.xx.3x.1xx" -Concatenate
    # 若需添加多个IP/主机,用逗号分隔
    # Set-Item WSMan:\localhost\Client\TrustedHosts -Value "10.xx.3x.1xx,10.xx.3x.2xx" -Concatenate
    
  • 第二步:执行Invoke-Command时明确指定域凭据
    $cred = Get-Credential "域名\用户名"
    Invoke-Command -ComputerName "10.xx.3x.1xx" -Credential $cred -ScriptBlock {Get-ADDefaultDomainPasswordPolicy}
    

2. 远程启用PSRemoting并恢复原状态

可以实现,步骤如下:

前提条件

  • 拥有目标主机的本地管理员权限
  • 目标主机SMB服务、WMI服务正常运行

步骤1:远程启用PSRemoting

通过WMI远程执行命令完成启用:

$targetHost = "目标主机名或IP"
$cred = Get-Credential "目标主机本地管理员账户"
# 远程执行Enable-PSRemoting,-Force跳过确认提示
Invoke-WmiMethod -ComputerName $targetHost -Credential $cred -Class Win32_Process -Name Create -ArgumentList "powershell.exe -Command Enable-PSRemoting -Force"

步骤2:执行所需远程命令

启用PSRemoting后,即可正常使用Invoke-Command执行任务:

Invoke-Command -ComputerName $targetHost -Credential $cred -ScriptBlock {
    # 替换为你需要执行的命令
    Get-ADDefaultDomainPasswordPolicy
}

步骤3:恢复原PSRemoting状态

先记录目标主机原本的配置,再逐一恢复:

# 1. 获取原WinRM服务的启动类型和运行状态
$originalWinRMConfig = Invoke-Command -ComputerName $targetHost -Credential $cred -ScriptBlock {
    $service = Get-Service WinRM
    return @{
        StartType = $service.StartType
        Status = $service.Status
    }
}

# 2. 恢复WinRM服务状态
Invoke-Command -ComputerName $targetHost -Credential $cred -ScriptBlock {
    Set-Service WinRM -StartType $using:originalWinRMConfig.StartType
    if ($using:originalWinRMConfig.Status -eq 'Stopped') {
        Stop-Service WinRM -Force
    }
}

# 3. 恢复WinRM防火墙规则(若原本未启用)
Invoke-Command -ComputerName $targetHost -Credential $cred -ScriptBlock {
    $rule = Get-NetFirewallRule -Name "WINRM-HTTP-In-TCP" -ErrorAction SilentlyContinue
    if ($rule -and $rule.Enabled -eq 'False') {
        Set-NetFirewallRule -Name "WINRM-HTTP-In-TCP" -Enabled False
    }
}

# 4. 若原本未配置WinRM监听,删除新增的监听端口
Invoke-Command -ComputerName $targetHost -Credential $cred -ScriptBlock {
    winrm delete winrm/config/listener?Address=*+Transport=HTTP
}

内容的提问来源于stack exchange,提问作者user1568050

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 09:25:26