Skip to content

Securing WinRM with TLS

3. Configure WinRM to Use HTTPS

Set the WinRM listener to use HTTPS and bind it to your certificate. Replace <thumbprint> with your certificate's thumbprint:

winrm create listener -transport https -certificate thumbprint="ABC123..."
Verify the listener configuration:
winrm get winrm/config/listener


5. Test TLS Connectivity

Validate the TLS configuration using PowerShell:

Test-WSMan -ComputerName <target> -Port 5986
Or use Invoke-Command to test the TLS handshake:
Invoke-Command -ComputerName <target> -Port 5986 -Credential <credential>
Check for successful connection and SSL/TLS handshake. Use Get-WinEvent -LogName System on the target server to verify WinRM-related events.


4. Set Authentication Method (Optional)

By default, WinRM uses Negotiate authentication. For enhanced security, enforce Kerberos or Basic (with proper IIS configuration):

winrm set winrm/config/service/auth @{Kerberos="true"}
If using Basic authentication, configure IIS to support it: 1. Open IIS Manager and select the server. 2. In the Features View, double-click Authentication. 3. Enable Basic Authentication and disable Windows Authentication. 4. Ensure the server is configured to use the certificate for secure communication.