Ansible通过WinRM连接Windows主机失败:凭据遭服务器拒绝
问题:Linux Zorin通过Ansible连接Windows主机失败,WinRM认证被拒
已完成的配置操作
- 在Windows主机安装并配置WinRM,开启Basic认证
- 将Windows网络连接类型改为专用
- 添加5985端口防火墙例外规则
- 通过
winrm configsddl default为用户赋予读取、执行权限 - Ansible hosts配置:
[win] <IP> [win:vars] ansible_user=<username> ansible_password=<password> ansible_connection=winrm ansible_winrm_scheme=http ansible_winrm_transport=basic ansible_winrm_port=5985 ansible_winrm_server_cert_validation=ignore
- 测试命令:
ansible win -i hosts -m win_ping
Windows主机当前WinRM配置
PS C:\WINDOWS\system32> winrm get winrm/config Config MaxEnvelopeSizekb = 500 MaxTimeoutms = 60000 MaxBatchItems = 32000 MaxProviderRequests = 4294967295 Client NetworkDelayms = 5000 URLPrefix = wsman AllowUnencrypted = true Auth Basic = true Digest = true Kerberos = true Negotiate = true Certificate = true CredSSP = false DefaultPorts HTTP = 5985 HTTPS = 5986 TrustedHosts Service RootSDDL = O:NSG:BAD:P(A;;GA;;;BA)(A;;GXGR;;;S-1-5-21-2039588290-1060779563-2652726705-1011)(A;;GR;;;IU)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD) MaxConcurrentOperations = 4294967295 MaxConcurrentOperationsPerUser = 1500 EnumerationTimeoutms = 240000 MaxConnections = 300 MaxPacketRetrievalTimeSeconds = 120 AllowUnencrypted = false Auth Basic = true Kerberos = true Negotiate = true Certificate = false CredSSP = false CbtHardeningLevel = Relaxed DefaultPorts HTTP = 5985 HTTPS = 5986 IPv4Filter = * IPv6Filter = * EnableCompatibilityHttpListener = false EnableCompatibilityHttpsListener = false CertificateThumbprint AllowRemoteAccess = true Winrs AllowRemoteShellAccess = true IdleTimeout = 7200000 MaxConcurrentUsers = 2147483647 MaxShellRunTime = 2147483647 MaxProcessesPerShell = 2147483647 MaxMemoryPerShellMB = 2147483647 MaxShellsPerUser = 2147483647
遇到的错误
- 开启Basic认证后,执行
win_ping返回:指定凭据被服务器拒绝 - 尝试设置
Service下的AllowUnencrypted = true时,报错:
WSManFault
Message
ProviderFault
WSManFault
Message = WinRM firewall exception will not work since one of the network connection types on this machine is set to Public. Change the network connection type to either Domain or Private and try again.
- 已将网络改为专用后,设置
AllowUnencrypted = true仍出现上述相同错误
解决方案建议
1. 修正WinRM服务端非加密连接配置
当前Service节点的AllowUnencrypted为false,这是Basic认证失败的核心原因(Basic认证依赖非加密HTTP连接)。执行以下命令修改:
winrm set winrm/config/service '@{AllowUnencrypted="true"}'
修改后执行winrm get winrm/config/service确认配置生效。
2. 确认用户权限
- 确保使用的
<username>属于Windows本地管理员组,或已被授予WinRM远程访问权限 - 执行以下命令为用户添加WinRM访问权限:
winrm configsddl default -u:<username> -p:<password>
3. 配置TrustedHosts
将Zorin控制主机的IP添加到Windows的WinRM信任列表:
Set-Item WSMan:\localhost\Client\TrustedHosts -Value "<Zorin主机IP>" -Concatenate
测试阶段可临时允许所有主机(生产环境不建议):
Set-Item WSMan:\localhost\Client\TrustedHosts -Value "*"
4. 重启WinRM服务
修改配置后必须重启服务:
Restart-Service winrm
5. 本地验证WinRM服务
在Windows主机执行以下命令,确认WinRM服务本身正常:
winrm id
返回正常XML信息则说明服务运行正常。
6. 切换Ansible认证方式(备选)
若Basic认证仍有问题,可尝试Negotiate认证,修改hosts文件中的传输方式:
ansible_winrm_transport=negotiate
该方式无需开启AllowUnencrypted,但要求控制主机与Windows主机处于同一域或已建立信任关系。
7. 重新配置防火墙规则
执行以下命令重新创建WinRM HTTP端口的防火墙允许规则:
netsh advfirewall firewall add rule name="WinRM-HTTP" dir=in action=allow protocol=TCP localport=5985 remoteip=<Zorin主机IP> profile=private
内容的提问来源于stack exchange,提问作者SKumar
相关产品推荐
相关产品推荐

