You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell免密建立远程会话时遇Kerberos认证错误(0x80090311)求助

PowerShell免密建立远程会话时遇Kerberos认证错误(0x80090311)求助

我来帮你分析下这个问题——你想用PowerShell免密建立远程PSSession,手动输入管理员凭证能正常连接,但通过脚本创建PSCredential对象免密登录时,碰到了Kerberos认证的0x80090311错误,而且已经确认远程服务器在WinRM的TrustedHosts列表里对吧?

先看你尝试的脚本代码:

$username = "Administrator"
$password = ConvertTo-SecureString "******" -AsPlainText -Force
$cred = New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList($username, $password)
$serverNameOrIp = "*****"
Enter-PSSession -ComputerName $serverNameOrIp -Credential $cred

你遇到的报错信息如下:

Enter-PSSession : Connecting to remote server ****** failed with the following error message : WinRM cannot
process the request. The following error with errorcode 0x80090311 occurred while using Kerberos authentication: There
are currently no logon servers available to service the logon request.

Possible causes are:
-The user name or password specified are invalid.
-Kerberos is used when no authentication method and no user name are specified.
-Kerberos accepts domain user names, but not local user names.
-The Service Principal Name (SPN) for the remote computer name and port does not exist.
-The client and remote computers are in different domains and there is no trust between the two domains.

After checking for the above issues, try the following:
-Check the Event Viewer for events related to authentication.
-Change the authentication method; add the destination computer to the WinRM TrustedHosts configuration setting or
use HTTPS transport.
Note that computers in the TrustedHosts list might not be authenticated.
-For more information about WinRM configuration, run the following command: winrm help config. For more
information, see the about_Remote_Troubleshooting Help topic.

At C:\Users\Administrator\Downloads\cred.ps1:6 char:1

  • Enter-PSSession -ComputerName $serverNameOrIp -Credential $cred
  • CategoryInfo : InvalidArgument: (******:String) [Enter-PSSession], PSRemotingTransportException
  • FullyQualifiedErrorId : CreateRemoteRunspaceFailed

结合你的场景和报错信息,核心问题出在Kerberos认证的局限性,下面给你针对性的解决思路:

方法1:强制使用NTLM认证

报错里明确提到“Kerberos accepts domain user names, but not local user names”,如果你用的Administrator是远程服务器的本地账户,Kerberos肯定会失败。此时只需要在Enter-PSSession命令里指定-Authentication NTLM参数,强制使用NTLM认证即可,修改后的脚本如下:

$username = "Administrator"
$password = ConvertTo-SecureString "******" -AsPlainText -Force
$cred = New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList($username, $password)
$serverNameOrIp = "*****"
Enter-PSSession -ComputerName $serverNameOrIp -Credential $cred -Authentication NTLM

这个方法是解决本地账户免密连接最直接的方案。

方法2:确认TrustedHosts配置正确生效

虽然你说已经把远程服务器加入TrustedHosts,但还是建议再检查一下配置是否正确:

  1. 查看当前TrustedHosts列表:
Get-Item WSMan:\localhost\Client\TrustedHosts
  1. 如果目标服务器不在列表里,用以下命令追加(避免覆盖已有配置):
Set-Item WSMan:\localhost\Client\TrustedHosts -Value "*****" -Concatenate

方法3:检查远程服务器的WinRM基础配置

确保远程服务器已经正确开启PowerShell远程功能,在远程主机上运行:

Enable-PSRemoting -Force

这条命令会自动完成WinRM服务启动、防火墙规则配置、远程权限设置等操作。

域环境额外注意事项(如果适用)

如果你是用域账户连接,还需要确认:

  • 客户端和远程服务器在同一域或存在域信任关系
  • 远程服务器的WinRM服务已注册正确的SPN记录,可通过以下命令查看:
setspn -L <远程服务器主机名>

需要确保存在WSMAN/<远程服务器主机名>和WSMAN/<远程服务器FQDN>这两条SPN记录,如果缺失,可以用setspn -S命令手动添加。

按照上面的方法调整后,应该就能顺利实现免密远程会话了。

备注:内容来源于stack exchange,提问作者Mohan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 12:54:30