WinRM客户端请求处理失败排查及远程启用PSRemoting可行性咨询
问题背景
我尝试运行以下命令:
Invoke-Command 10.xx.3x.1xx -ScriptBlock {Get-ADDefaultDomainPasswordPolicy}
但出现错误:
OpenError: [10.xx.3x.1xx] 连接远程服务器10.xx.3x.1xx失败,错误信息如下:The WinRM client cannot process the request. 使用IP地址进行默认认证需满足以下条件:传输协议为HTTPS,或目标主机在TrustedHosts列表中且提供明确凭据。请使用winrm.cmd配置TrustedHosts。注意TrustedHosts列表中的计算机可能未经过身份验证。如需了解设置TrustedHosts的更多信息,请运行命令:winrm help config。更多信息请查看about_Remote_Troubleshooting帮助主题。
这些主机均在域内,且与域内另一主机通信正常。我从发起命令的远程机器执行Test-WsMan host_ip命令,返回结果如下:
wsmid : http://schemas.dmtf.org/wbem/wsman/identity/1/wsmanidentity.xsd
ProtocolVersion : http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd
ProductVendor : Microsoft Corporation
ProductVersion : OS: 0.0.0 SP: 0.0 Stack: 3.0
我还在远程主机重新执行了Enable-PSRemoting(执行后无返回信息),但仍出现上述错误。
现咨询两个问题:
- 最关注的问题:如何解决当前报错?
- 能否远程启用未允许PS远程执行的主机,待命令执行成功后恢复其原状态?
问题解答
1. 解决当前报错的方法
根据错误提示,核心原因是使用IP地址进行WinRM远程连接时的认证限制,结合域环境,有两种直接可行的方案:
方案一:使用主机名而非IP地址连接
域环境下优先使用目标主机的完全限定域名(FQDN)或NetBIOS名,可直接利用Kerberos认证,无需额外配置TrustedHosts:
# 使用完全限定域名 Invoke-Command -ComputerName "目标主机名.域名后缀" -ScriptBlock {Get-ADDefaultDomainPasswordPolicy} # 或使用NetBIOS名 Invoke-Command -ComputerName "目标主机名" -ScriptBlock {Get-ADDefaultDomainPasswordPolicy}
方案二:配置TrustedHosts并提供明确凭据
如果必须使用IP地址连接,按以下步骤操作:
- 第一步:在发起命令的本地机器上,将目标IP添加到TrustedHosts列表
# 添加单个IP(-Concatenate参数保留原有列表内容) Set-Item WSMan:\localhost\Client\TrustedHosts -Value "10.xx.3x.1xx" -Concatenate # 若需添加多个IP/主机,用逗号分隔 # Set-Item WSMan:\localhost\Client\TrustedHosts -Value "10.xx.3x.1xx,10.xx.3x.2xx" -Concatenate - 第二步:执行
Invoke-Command时明确指定域凭据$cred = Get-Credential "域名\用户名" Invoke-Command -ComputerName "10.xx.3x.1xx" -Credential $cred -ScriptBlock {Get-ADDefaultDomainPasswordPolicy}
2. 远程启用PSRemoting并恢复原状态
可以实现,步骤如下:
前提条件
- 拥有目标主机的本地管理员权限
- 目标主机SMB服务、WMI服务正常运行
步骤1:远程启用PSRemoting
通过WMI远程执行命令完成启用:
$targetHost = "目标主机名或IP" $cred = Get-Credential "目标主机本地管理员账户" # 远程执行Enable-PSRemoting,-Force跳过确认提示 Invoke-WmiMethod -ComputerName $targetHost -Credential $cred -Class Win32_Process -Name Create -ArgumentList "powershell.exe -Command Enable-PSRemoting -Force"
步骤2:执行所需远程命令
启用PSRemoting后,即可正常使用Invoke-Command执行任务:
Invoke-Command -ComputerName $targetHost -Credential $cred -ScriptBlock { # 替换为你需要执行的命令 Get-ADDefaultDomainPasswordPolicy }
步骤3:恢复原PSRemoting状态
先记录目标主机原本的配置,再逐一恢复:
# 1. 获取原WinRM服务的启动类型和运行状态 $originalWinRMConfig = Invoke-Command -ComputerName $targetHost -Credential $cred -ScriptBlock { $service = Get-Service WinRM return @{ StartType = $service.StartType Status = $service.Status } } # 2. 恢复WinRM服务状态 Invoke-Command -ComputerName $targetHost -Credential $cred -ScriptBlock { Set-Service WinRM -StartType $using:originalWinRMConfig.StartType if ($using:originalWinRMConfig.Status -eq 'Stopped') { Stop-Service WinRM -Force } } # 3. 恢复WinRM防火墙规则(若原本未启用) Invoke-Command -ComputerName $targetHost -Credential $cred -ScriptBlock { $rule = Get-NetFirewallRule -Name "WINRM-HTTP-In-TCP" -ErrorAction SilentlyContinue if ($rule -and $rule.Enabled -eq 'False') { Set-NetFirewallRule -Name "WINRM-HTTP-In-TCP" -Enabled False } } # 4. 若原本未配置WinRM监听,删除新增的监听端口 Invoke-Command -ComputerName $targetHost -Credential $cred -ScriptBlock { winrm delete winrm/config/listener?Address=*+Transport=HTTP }
内容的提问来源于stack exchange,提问作者user1568050

