1. 程式人生 > >CS2: Server 2003 enter-pssession 連接到另外一臺服務器報錯

CS2: Server 2003 enter-pssession 連接到另外一臺服務器報錯

ipa sport sp2 com 報錯 enter hang nts sets

客戶問題概括:
用戶反饋在域中一臺Win 2003 SP2 服務器使用 Powershell ,“enter-pssession” 鏈接到另外一臺服務器無法工作,該服務器無其他問題.
報錯內容:

WSManFault
Message = WinRM cannot process the request. The following error occured while using Negotiate authentication: An unknown security error occurred.
Possible causes are:
-The user name or password specified are invalid.

-Kerberos is used when no authentication method and no user name are specified.
-Kerberos accepts domain user names, but not local user names.
-The Service Principal Name (SPN) for the remote computer name and port does not exist.
-The client and remote computers are in different domains and there is no trust between the two domains.
After checking for the above issues, try the following:
-Check the Event Viewer for events related to authentication.
-Change the authentication method; add the destination computer to the WinRM TrustedHosts configuration setting or use
HTTPS transport.
Note that computers in the TrustedHosts list might not be authenticated.
-For more information about WinRM configuration, run the following command: winrm help config.

解決方法:
排查安全日誌發現此服務器SPN註冊有問題,重新註冊spn後即可, 註冊spn工具為setspn.exe

舉例:

setspn -l HTTP/Servername 確認SPN

setspn -q HTTP/Servername.fqdn

發現重復SPN

setspn -x刪除重復spn

CS2: Server 2003 enter-pssession 連接到另外一臺服務器報錯