You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible通过WinRM连接Windows主机失败:凭据遭服务器拒绝

问题:Linux Zorin通过Ansible连接Windows主机失败,WinRM认证被拒

已完成的配置操作

  • 在Windows主机安装并配置WinRM,开启Basic认证
  • 将Windows网络连接类型改为专用
  • 添加5985端口防火墙例外规则
  • 通过winrm configsddl default为用户赋予读取、执行权限
  • Ansible hosts配置:
[win]
<IP>

[win:vars]
ansible_user=<username>
ansible_password=<password>
ansible_connection=winrm
ansible_winrm_scheme=http
ansible_winrm_transport=basic
ansible_winrm_port=5985
ansible_winrm_server_cert_validation=ignore
  • 测试命令:ansible win -i hosts -m win_ping

Windows主机当前WinRM配置

PS C:\WINDOWS\system32> winrm get winrm/config
Config
    MaxEnvelopeSizekb = 500
    MaxTimeoutms = 60000
    MaxBatchItems = 32000
    MaxProviderRequests = 4294967295
    Client
        NetworkDelayms = 5000
        URLPrefix = wsman
        AllowUnencrypted = true
        Auth
            Basic = true
            Digest = true
            Kerberos = true
            Negotiate = true
            Certificate = true
            CredSSP = false
        DefaultPorts
            HTTP = 5985
            HTTPS = 5986
        TrustedHosts
    Service
        RootSDDL = O:NSG:BAD:P(A;;GA;;;BA)(A;;GXGR;;;S-1-5-21-2039588290-1060779563-2652726705-1011)(A;;GR;;;IU)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)
        MaxConcurrentOperations = 4294967295
        MaxConcurrentOperationsPerUser = 1500
        EnumerationTimeoutms = 240000
        MaxConnections = 300
        MaxPacketRetrievalTimeSeconds = 120
        AllowUnencrypted = false
        Auth
            Basic = true
            Kerberos = true
            Negotiate = true
            Certificate = false
            CredSSP = false
            CbtHardeningLevel = Relaxed
        DefaultPorts
            HTTP = 5985
            HTTPS = 5986
        IPv4Filter = *
        IPv6Filter = *
        EnableCompatibilityHttpListener = false
        EnableCompatibilityHttpsListener = false
        CertificateThumbprint
        AllowRemoteAccess = true
    Winrs
        AllowRemoteShellAccess = true
        IdleTimeout = 7200000
        MaxConcurrentUsers = 2147483647
        MaxShellRunTime = 2147483647
        MaxProcessesPerShell = 2147483647
        MaxMemoryPerShellMB = 2147483647
        MaxShellsPerUser = 2147483647

遇到的错误

  1. 开启Basic认证后,执行win_ping返回:指定凭据被服务器拒绝
  2. 尝试设置Service下的AllowUnencrypted = true时,报错:

WSManFault
Message
ProviderFault
WSManFault
Message = WinRM firewall exception will not work since one of the network connection types on this machine is set to Public. Change the network connection type to either Domain or Private and try again.

  1. 已将网络改为专用后,设置AllowUnencrypted = true仍出现上述相同错误

解决方案建议

1. 修正WinRM服务端非加密连接配置

当前Service节点的AllowUnencrypted为false,这是Basic认证失败的核心原因(Basic认证依赖非加密HTTP连接)。执行以下命令修改:

winrm set winrm/config/service '@{AllowUnencrypted="true"}'

修改后执行winrm get winrm/config/service确认配置生效。

2. 确认用户权限

  • 确保使用的<username>属于Windows本地管理员组,或已被授予WinRM远程访问权限
  • 执行以下命令为用户添加WinRM访问权限:
winrm configsddl default -u:<username> -p:<password>

3. 配置TrustedHosts

将Zorin控制主机的IP添加到Windows的WinRM信任列表:

Set-Item WSMan:\localhost\Client\TrustedHosts -Value "<Zorin主机IP>" -Concatenate

测试阶段可临时允许所有主机(生产环境不建议):

Set-Item WSMan:\localhost\Client\TrustedHosts -Value "*"

4. 重启WinRM服务

修改配置后必须重启服务:

Restart-Service winrm

5. 本地验证WinRM服务

在Windows主机执行以下命令,确认WinRM服务本身正常:

winrm id

返回正常XML信息则说明服务运行正常。

6. 切换Ansible认证方式(备选)

若Basic认证仍有问题,可尝试Negotiate认证,修改hosts文件中的传输方式:

ansible_winrm_transport=negotiate

该方式无需开启AllowUnencrypted,但要求控制主机与Windows主机处于同一域或已建立信任关系。

7. 重新配置防火墙规则

执行以下命令重新创建WinRM HTTP端口的防火墙允许规则:

netsh advfirewall firewall add rule name="WinRM-HTTP" dir=in action=allow protocol=TCP localport=5985 remoteip=<Zorin主机IP> profile=private

内容的提问来源于stack exchange,提问作者SKumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 19:39:45