top of page

General discussion

Public·1 member

User-ID Agentless - WinRM over HTTP with or without using Kerberos ( Kerberos or Basic-Simple Authentication )

User-ID Agentless WinRM over HTTP with or without using Kerberos ( Kerberos or Basic- simple-Authentication )

Hello community, how are you, good evening, thanks for your time and collaboration.

I have a question regarding the use of WinRM over HTTP.

According to this link there are 3 mechanisms of use:

Configure WinRM over HTTPS with Basic Authentication

Configure WinRM over HTTP with Kerberos

Configure WinRM over HTTPS with Kerberos

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-server-monitoring-using-winrm#:~:text=There%20are%20three%20ways%20to%20configure%20server%20monitoring%20using%20WinRM%3A

Now reviewing this link that mentions 4 possible options to solve an issue, option 3 talks about changing the transport-Protocol type to WinRM-HTTP and done:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004MI6CAM#:~:text=Option%203%3A%20Switch%20to%20WinRM%20transport%20protocol

Currently using WMI, but we want to switch to using WinRM-HTTP to avoid errors, issues and problems.

-Now my doubt is the following, with respect to WinRM-HTTP can I use simple authentication ? or must be mandatory the use of Kerberos for WinRM-HTTP authentication with Kerberos? Is it mandatory to use Kerberos using a Kerberos profile ? or just switching to WinRM-HTTP, in Monitored Server (already the credentials are OK and making sure that the Domain Controller server(s) have up and running WinRM-HTTP service/listener is sufficient ? This is because the server administrators are somewhat reluctant and refuse to apply settings on their servers, at most we can validate the WinRM service running and the listener, but nothing more, thinking of switching to the use of WimRM to use Kerberos authentication and / or use HTTPS using a certificate will not want to do so to not adjust anything more than hopefully lift the service.

Thank you, I remain attentive to your comments, advice, good collaboration, suggestions.

Best Regards

1173 Views
Reaper
Reaper
Dec 02, 2022

Using basic auth over http would mean exposing your service account in cleartext every time the firewall performs a log-read on the AD (every second) so technically it would be possible but it was not made available due to poor security I think You can always submit a feature request :)

  • Whatsapp
  • Amazon
  • X
  • LinkedIn

Contact
PANgurus BV
VAT: BE0769507136
INFO@PANGURUS.COM
+32 (486) 986 753

©2020 by PANgurus.

bottom of page