Securing WinRM with TLS
3. Configure WinRM to Use HTTPS¶
Set the WinRM listener to use HTTPS and bind it to your certificate. Replace <thumbprint> with your certificate's thumbprint:
5. Test TLS Connectivity¶
Validate the TLS configuration using PowerShell:
Or useInvoke-Command to test the TLS handshake:
Check for successful connection and SSL/TLS handshake. Use Get-WinEvent -LogName System on the target server to verify WinRM-related events.
4. Set Authentication Method (Optional)¶
By default, WinRM uses Negotiate authentication. For enhanced security, enforce Kerberos or Basic (with proper IIS configuration):