winrs可正常连接但pywinrm返回凭据被服务器拒绝错误的排查求助
问题:pywinrm Kerberos认证失败(winrs可正常连接)
当前环境中,使用winrs能成功连接远程Windows机器,但用pywinrm时,不管在Windows还是Linux系统上,都会返回the specified credentials were rejected by the server错误。
远程Windows机器WinRM服务认证配置
winrm get winrm/config/service/auth Auth Basic = false [Source="GPO"] Kerberos = true [Source="GPO"] Negotiate = false [Source="GPO"] Certificate = false CredSSP = false [Source="GPO"] CbtHardeningLevel = Strict [Source="GPO"]
Windows环境报错信息
import winrm sess = winrm.Session('<hostname>', auth=('MOzsoy', '***'), transport='kerberos') sess.run_cmd('hostname') Traceback (most recent call last): File "C:\Users\mozsoy\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.10_qbz5n2kfra8p0\LocalCache\local-packages\Python310\site-packages\winrm\transport.py", line 328, in _send_message_request response.raise_for_status() File "C:\Users\mozsoy\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.10_qbz5n2kfra8p0\LocalCache\local-packages\Python310\site-packages\requests\models.py", line 1021, in raise_for_status raise HTTPError(http_error_msg, response=self) requests.exceptions.HTTPError: 401 Client Error: for url: http://<hostname>:5985/wsman During handling of the above exception, another exception occurred: Traceback (most recent call last): File "<stdin>", line 1, in <module> File "C:\Users\mozsoy\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.10_qbz5n2kfra8p0\LocalCache\local-packages\Python310\site-packages\winrm\__init__.py", line 40, in run_cmd shell_id = self.protocol.open_shell() File "C:\Users\mozsoy\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.10_qbz5n2kfra8p0\LocalCache\local-packages\Python310\site-packages\winrm\protocol.py", line 166, in open_shell res = self.send_message(xmltodict.unparse(req)) File "C:\Users\mozsoy\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.10_qbz5n2kfra8p0\LocalCache\local-packages\Python310\site-packages\winrm\protocol.py", line 243, in send_message resp = self.transport.send_message(message) File "C:\Users\mozsoy\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.10_qbz5n2kfra8p0\LocalCache\local-packages\Python310\site-packages\winrm\transport.py", line 322, in send_message response = self._send_message_request(prepared_request, message) File "C:\Users\mozsoy\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.10_qbz5n2kfra8p0\LocalCache\local-packages\Python310\site-packages\winrm\transport.py", line 332, in _send_message_request raise InvalidCredentialsError("the specified credentials were rejected by the server") winrm.exceptions.InvalidCredentialsError: the specified credentials were rejected by the server
Linux环境报错信息
import winrm sess = winrm.Session('<hostname>', auth=('MOzsoy', '***'), transport='kerberos') sess.run_cmd("hostname") /home/mozsoy/.local/lib/python3.7/site-packages/winrm/vendor/requests_kerberos/kerberos_.py:176: NoCertificateRetrievedWarning: Requests is running with a non urllib3 backend, cannot retrieve server certificate for CBT NoCertificateRetrievedWarning) Traceback (most recent call last): File "/home/mozsoy/.local/lib/python3.7/site-packages/winrm/transport.py", line 328, in _send_message_request response.raise_for_status() File "/usr/lib/python3/dist-packages/requests/models.py", line 840, in raise_for_status raise HTTPError(http_error_msg, response=self) requests.exceptions.HTTPError: 401 Client Error: for url: http://<hostname>:5985/wsman During handling of the above exception, another exception occurred: Traceback (most recent call last): File "<stdin>", line 1, in <module> File "/home/mozsoy/.local/lib/python3.7/site-packages/winrm/__init__.py", line 40, in run_cmd shell_id = self.protocol.open_shell() File "/home/mozsoy/.local/lib/python3.7/site-packages/winrm/protocol.py", line 166, in open_shell res = self.send_message(xmltodict.unparse(req)) File "/home/mozsoy/.local/lib/python3.7/site-packages/winrm/protocol.py", line 243, in send_message resp = self.transport.send_message(message) File "/home/mozsoy/.local/lib/python3.7/site-packages/winrm/transport.py", line 309, in send_message self.build_session() File "/home/mozsoy/.local/lib/python3.7/site-packages/winrm/transport.py", line 292, in build_session self.setup_encryption() File "/home/mozsoy/.local/lib/python3.7/site-packages/winrm/transport.py", line 298, in setup_encryption self._send_message_request(prepared_request, '') File "/home/mozsoy/.local/lib/python3.7/site-packages/winrm/transport.py", line 332, in _send_message_request raise InvalidCredentialsError("the specified credentials were rejected by the server") winrm.exceptions.InvalidCredentialsError: the specified credentials were rejected by the server
调试步骤
- 检查Kerberos票据有效性:
Windows上运行klist,查看是否有针对远程主机SPN的有效票据;Linux上先执行kinit MOzsoy@DOMAIN.COM(替换为实际域名)获取票据,再用klist确认,之后重试pywinrm连接。 - 验证SPN配置:
在远程Windows主机上运行setspn -L <hostname>,确认存在WSMAN/<hostname>和WSMAN/<hostname.domain.com>这两个SPN,若缺失需管理员添加。 - 补全域信息:
pywinrm使用Kerberos时,用户名必须包含域,比如auth=('DOMAIN\\MOzsoy', '***')或auth=('MOzsoy@DOMAIN.COM', '***'),避免仅用裸用户名导致认证失败。 - 排查CBT配置影响:
远程主机CbtHardeningLevel = Strict,Linux端报错显示无法获取服务器证书,可尝试升级requests-kerberos和urllib3版本;测试场景下可临时调整CBT级别(需管理员权限):winrm set winrm/config/service @{CbtHardeningLevel="Relaxed"}。 - 开启WinRM详细日志:
在远程主机执行以下命令开启日志:
然后查看winrm set winrm/config/service/tracing @{Enabled="true"; Level="verbose"}C:\Windows\System32\winevt\Logs\Microsoft-Windows-WinRM%4Operational.evtx,定位具体认证失败原因。 - 抓包对比请求差异:
用Wireshark分别捕获winrs和pywinrm的Kerberos流量,对比AS-REQ、TGS-REQ、AP-REQ包的SPN、加密类型等参数差异。
内容的提问来源于stack exchange,提问作者user2475552
相关产品推荐
相关产品推荐

