Windows10 WSL安装Ansible后执行win_ping遇协议违规EOF错误求助
Alright, let's break down this UNREACHABLE! error with EOF occurred in violation of protocol you're seeing when running win_ping from your WSL Ubuntu setup. This almost always boils down to misconfigured WinRM on your Windows target machine, or missing Ansible settings to handle WinRM's SSL behavior. Here's how to fix it step by step:
1. First, Fix WinRM Configuration on Your Windows 10 Target
WinRM is the Windows remote management service that Ansible relies on to communicate with Windows machines, and it’s rarely properly configured out of the box. Open PowerShell as Administrator on your 192.168.6.1 machine and run these commands:
Enable WinRM and Basic Authentication (Test/Dev Use)
For testing purposes (skip the unencrypted setting in production), run:
# Enable WinRM and set up core remote management settings Enable-PSRemoting -Force # Allow unencrypted traffic (only for testing environments!) winrm set winrm/config/service '@{AllowUnencrypted="true"}' # Enable basic authentication, required for Ansible's basic transport method winrm set winrm/config/service/auth '@{Basic="true"}'
Optional: Configure HTTPS WinRM (Production-Friendly)
If you want to use HTTPS (recommended for production), generate a self-signed certificate and create an HTTPS listener:
# Generate a self-signed certificate for the Windows machine $cert = New-SelfSignedCertificate -DnsName "your-windows-machine-hostname" -CertStoreLocation "Cert:\LocalMachine\My" # Create an HTTPS WinRM listener using the generated certificate winrm create winrm/config/Listener?Address=*+Transport=HTTPS "@{Hostname=`"your-windows-machine-hostname`"; CertificateThumbprint=`"$($cert.Thumbprint)`"}"
Verify WinRM Listeners
Confirm the listener is active with:
winrm enumerate winrm/config/listener
You should see either an HTTP listener on port 5985 or an HTTPS listener on port 5986.
2. Update Your Ansible Inventory/Playbook Settings
You need to explicitly tell Ansible how to connect to your Windows machine. Here are working examples:
Example Inventory File (inventory.ini)
[windows] 192.168.6.1 ansible_user=YOUR_WINDOWS_ADMIN_USER ansible_password=YOUR_WINDOWS_PASSWORD ansible_connection=winrm ansible_winrm_transport=basic ansible_winrm_server_cert_validation=ignore ansible_port=5985
- Use
ansible_port=5986instead if you set up HTTPS. ansible_winrm_server_cert_validation=ignoreis critical for self-signed HTTPS certificates (Ansible will reject untrusted certificates by default).
Example Playbook
- name: Test Windows connectivity hosts: 192.168.6.1 vars: ansible_connection: winrm ansible_winrm_transport: basic ansible_winrm_server_cert_validation: ignore ansible_port: 5985 ansible_user: "YOUR_WINDOWS_ADMIN_USER" ansible_password: "YOUR_WINDOWS_PASSWORD" tasks: - name: Ping the Windows machine win_ping:
3. Verify Network Connectivity from WSL
Make sure your WSL instance can reach the Windows target's WinRM port. Run this in WSL:
# Test HTTP port nc -zv 192.168.6.1 5985 # Or test HTTPS port if using that setup nc -zv 192.168.6.1 5986
If this fails, check the Windows Firewall on the target—allow inbound traffic for WinRM (ports 5985/5986) or temporarily disable the firewall for testing.
4. Update PyWinRM and Ansible
Older versions of pywinrm or Ansible can have SSL handshake bugs. Run these in WSL to upgrade:
# Upgrade pywinrm to the latest version pip install --upgrade pywinrm --user # Upgrade Ansible to the latest compatible version pip install --upgrade ansible --user
Also, double-check that your PATH includes ~/.local/bin (run echo $PATH). If not, reload your bashrc to apply the path change:
source ~/.bashrc
After following these steps, re-run your win_ping playbook—it should connect successfully without the SSL/protocol error.
内容的提问来源于stack exchange,提问作者Chanond Wongpiya

