Guide to setup Ansible for AD controlled machines using GPO and AD CA
Ansible uses WinRM by default, and this guide configures it to use Kerberos authentication and https
Allowing remote management
- Computer Configuration -> Policies -> Administrative Templates -> Windows Components -> Windows Remote Management (WinRM) -> WinRM Service -> Allow remote server management through WinRM -> Enabled
Enabling the WinRM Service on Startup
- Computer Configuration -> Policies -> Windows Settings -> Security Settings -> System Services -> Windows Remote Management (WS-Management) -> Automatic
Allowing WinRM through the Firewall
- Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Windows Defender Firewall with Advanced Security -> Inbound Rules
- Create a new rule -> TCP Port: 5986 -> Allow -> Only leave domain checked
In the GPO from steps 1/2:
- Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Public Key Policies -> Certificate Service Client - Auto-Enrollment
- Set configuration model to enabled and check both boxes
- Open the certificate authority panel and navigate to your CA
- Right click certificate templates -> Manage
- Right click Web Server -> Duplicate
- Set your certificate name in the general tab
- In subject name choose build from this AD information
- Change subject name format to common name
- Leave only the DNS name box checked
- In the security tab, add the group/user you want to manage
- Under permissions for this user/group, check read, enroll, and autoenroll
- Save the certificate template and close the CA console, but not the original panel
- Right click certificate template -> new -> certificate template to issue -> find your new certificate template
This step will depend on the OS/Distro of your Ansible host; follow the Ansible documentation for this
- Navigate to your Ansible hosts file
- Make sure the Windows machines you are managing are in a group, I have mine named windesktop
- Configure as shown:
[windesktop:vars]
ansible_user=Administrator@DOMAIN.NAME
ansible_port=5986
ansible_connection=winrm
ansible_winrm_transport=kerberos
ansible_winrm_scheme=https- To obtain a Kerberos ticket for authentication run the following on the Ansible host:
kinit Administrator@DOMAIN.NAMETo connect with https, we will need to add our CA to our trust store
- On the Windows server with CA, open the CA panel
- Right click on your CA server name and open the properties menu
- Select Certificate #0 and click view certificate
- Open the details tab and select copy to file
- Select DER .CER and export the file, here I used caCert.cer
- Copy the file to your Ansible host, I used scp but you can use a shared folder or other method
In order for OpenSSL to read the certificate, we need to convert it
openssl x509 -inform DER -outform PEM -in caCert.cer -out caCert.crtsudo cp caCert.crt /usr/local/share/ca-certificates
sudo update-ca-certificatesAt this point, you should be good to go. To test, from your Ansible host run the following:
ansible windesktop -m win_pingYou should receive a SUCCESS with a pong message, and the output should be highlighted green instead of red