PowerShell免密建立远程会话时遇Kerberos认证错误(0x80090311)求助
我来帮你分析下这个问题——你想用PowerShell免密建立远程PSSession,手动输入管理员凭证能正常连接,但通过脚本创建PSCredential对象免密登录时,碰到了Kerberos认证的0x80090311错误,而且已经确认远程服务器在WinRM的TrustedHosts列表里对吧?
先看你尝试的脚本代码:
$username = "Administrator" $password = ConvertTo-SecureString "******" -AsPlainText -Force $cred = New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList($username, $password) $serverNameOrIp = "*****" Enter-PSSession -ComputerName $serverNameOrIp -Credential $cred
你遇到的报错信息如下:
Enter-PSSession : Connecting to remote server ****** failed with the following error message : WinRM cannot
process the request. The following error with errorcode 0x80090311 occurred while using Kerberos authentication: There
are currently no logon servers available to service the logon request.Possible causes are:
-The user name or password specified are invalid.
-Kerberos is used when no authentication method and no user name are specified.
-Kerberos accepts domain user names, but not local user names.
-The Service Principal Name (SPN) for the remote computer name and port does not exist.
-The client and remote computers are in different domains and there is no trust between the two domains.After checking for the above issues, try the following:
-Check the Event Viewer for events related to authentication.
-Change the authentication method; add the destination computer to the WinRM TrustedHosts configuration setting or
use HTTPS transport.
Note that computers in the TrustedHosts list might not be authenticated.
-For more information about WinRM configuration, run the following command: winrm help config. For more
information, see the about_Remote_Troubleshooting Help topic.At C:\Users\Administrator\Downloads\cred.ps1:6 char:1
- Enter-PSSession -ComputerName $serverNameOrIp -Credential $cred
- CategoryInfo : InvalidArgument: (******:String) [Enter-PSSession], PSRemotingTransportException
- FullyQualifiedErrorId : CreateRemoteRunspaceFailed
结合你的场景和报错信息,核心问题出在Kerberos认证的局限性,下面给你针对性的解决思路:
方法1:强制使用NTLM认证
报错里明确提到“Kerberos accepts domain user names, but not local user names”,如果你用的Administrator是远程服务器的本地账户,Kerberos肯定会失败。此时只需要在Enter-PSSession命令里指定-Authentication NTLM参数,强制使用NTLM认证即可,修改后的脚本如下:
$username = "Administrator" $password = ConvertTo-SecureString "******" -AsPlainText -Force $cred = New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList($username, $password) $serverNameOrIp = "*****" Enter-PSSession -ComputerName $serverNameOrIp -Credential $cred -Authentication NTLM
这个方法是解决本地账户免密连接最直接的方案。
方法2:确认TrustedHosts配置正确生效
虽然你说已经把远程服务器加入TrustedHosts,但还是建议再检查一下配置是否正确:
- 查看当前TrustedHosts列表:
Get-Item WSMan:\localhost\Client\TrustedHosts
- 如果目标服务器不在列表里,用以下命令追加(避免覆盖已有配置):
Set-Item WSMan:\localhost\Client\TrustedHosts -Value "*****" -Concatenate
方法3:检查远程服务器的WinRM基础配置
确保远程服务器已经正确开启PowerShell远程功能,在远程主机上运行:
Enable-PSRemoting -Force
这条命令会自动完成WinRM服务启动、防火墙规则配置、远程权限设置等操作。
域环境额外注意事项(如果适用)
如果你是用域账户连接,还需要确认:
- 客户端和远程服务器在同一域或存在域信任关系
- 远程服务器的WinRM服务已注册正确的SPN记录,可通过以下命令查看:
setspn -L <远程服务器主机名>
需要确保存在WSMAN/<远程服务器主机名>和WSMAN/<远程服务器FQDN>这两条SPN记录,如果缺失,可以用setspn -S命令手动添加。
按照上面的方法调整后,应该就能顺利实现免密远程会话了。
备注:内容来源于stack exchange,提问作者Mohan

