码迷,mamicode.com
首页 > 其他好文 > 详细

CS2: Server 2003 enter-pssession 连接到另外一台服务器报错

时间:2018-01-21 19:12:42      阅读:168      评论:0      收藏:0      [点我收藏+]

标签:dom   sts   different   win   password   request   got   ann   com   

客户问题概括:
用户反馈在域中一台Win 2003 SP2 服务器使用 Powershell ,“enter-pssession” 链接到另外一台服务器无法工作,该服务器无其他问题.
报错内容:

WSManFault
Message = WinRM cannot process the request. The following error occured while using Negotiate authentication: An unknown security error occurred.
Possible causes are:
-The user name or password specified are invalid.
-Kerberos is used when no authentication method and no user name are specified.
-Kerberos accepts domain user names, but not local user names.
-The Service Principal Name (SPN) for the remote computer name and port does not exist.
-The client and remote computers are in different domains and there is no trust between the two domains.
After checking for the above issues, try the following:
-Check the Event Viewer for events related to authentication.
-Change the authentication method; add the destination computer to the WinRM TrustedHosts configuration setting or use
HTTPS transport.
Note that computers in the TrustedHosts list might not be authenticated.
-For more information about WinRM configuration, run the following command: winrm help config.

解决方法:
排查安全日志发现此服务器SPN注册有问题,重新注册spn后即可, 注册spn工具为setspn.exe

举例:

setspn -l HTTP/Servername 确认SPN

setspn -q HTTP/Servername.fqdn

发现重复SPN

setspn -x删除重复spn

CS2: Server 2003 enter-pssession 连接到另外一台服务器报错

标签:dom   sts   different   win   password   request   got   ann   com   

原文地址:http://blog.51cto.com/13133729/2063421

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!