# Winrm

**URL:** <https://discourse.chef.io/t/winrm/6859>\
**Category:** Chef Infra (archive)\
**Created:** [August 6, 2015, 5:02pm UTC](https://discourse.chef.io/t/winrm/6859 "2015-08-06T17:02:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhil\_Shah](https://avatars.discourse-cdn.com/v4/letter/n/f17d59/32.png) [@Nikhil\_Shah](https://discourse.chef.io/u/Nikhil_Shah)\
**Post date:** [August 6, 2015, 5:02pm UTC](https://discourse.chef.io/t/winrm/6859/1 "2015-08-06T17:02:54Z")

</div>

Hey guys,

It's been a while since i started bootstrapping windows machines since I've  
been doing linux for so long, I've enabled winrm and setup the proper  
configs for winrm. However, I am getting the following error and was hoping  
someone can lead me to the right place:

eset-era01.theorchard.local C:\Users\Administrator\>chef-client -c

> # c:/chef/client.rb -j c:/chef/first-boot.json -E DEVELOPMENT eset-era01.theorchard.local [2015-08-06T12:44:45-04:00] INFO: \*\*\* Chef 12.4.1 \*\*\* eset-era01.theorchard.local [2015-08-06T12:44:45-04:00] INFO: Chef-client pid: 4104 eset-era01.theorchard.local [2015-08-06T12:45:18-04:00] INFO: Client key c:/chef/client.pem is not present - registering eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: SSL Validation failure connecting to host: chef01.theorchard.local - SSL\_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed eset-era01.theorchard.local eset-era01.theorchard.local
> 
> # eset-era01.theorchard.local Chef encountered an error attempting to create the client "eset-era01.TheOrchard.local" eset-era01.theorchard.local
> 
> eset-era01.theorchard.local  
> eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: Running  
> exception handlers  
> eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: Exception  
> handlers complete  
> eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] FATAL: Stacktrace  
> dumped to c:/chef/cache/chef-stacktrace.out  
> eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] FATAL:  
> OpenSSL::SSL::SSLError: SSL\_connect returned=1 errno=0 state=SSLv3 read  
> server certificate B: certificate verify failed

--  
_Nikhil Shah_ • _System Administrator_  
[nshah@theorchard.com](mailto:nshah@theorchard.com) • _p._ (+1) 212 308-5648

THE ORCHARD _Distribution Done Right_  
23 E 4th St Fl 3, New York, NY 10003

> **[The Orchard](https://www.theorchard.com)**
>
> What started as a revolutionary music distribution company, continues to evolve but never loses sight of its main purpose: to empower creators to grow and adapt in the dynamic, global industry.

_Follow us:_ The Daily Rind [http://www.dailyrindblog.com/](http://www.dailyrindblog.com/) • Facebook  
[http://www.facebook.com/theorchard](http://www.facebook.com/theorchard) • Twitter  
[http://www.twitter.com/orchtweets](http://www.twitter.com/orchtweets) • YouTube  
[http://www.youtube.com/user/theorchard](http://www.youtube.com/user/theorchard) • LinkedIn  
[http://www.linkedin.com/company/the-orchard](http://www.linkedin.com/company/the-orchard)

_Privileged And Confidential Communication._ This electronic transmission,  
and any documents attached hereto, (a) are protected by the Electronic  
Communications Privacy Act (18 USC §§ 2510-2521), (b) may contain  
confidential and/or legally privileged information, and (c) are for the  
sole use of the intended recipient named above. If you have received this  
electronic message in error, please notify the sender and delete the  
electronic message. Any disclosure, copying, distribution, or use of the  
contents of the information received in error is strictly prohibited.

---

<div class="post-metadata">

**Author:** ![Taras\_Klym](https://avatars.discourse-cdn.com/v4/letter/t/f08c70/32.png) [@Taras\_Klym](https://discourse.chef.io/u/Taras_Klym)\
**Post date:** [August 6, 2015, 8:16pm UTC](https://discourse.chef.io/t/winrm/6859/2 "2015-08-06T20:16:54Z")

</div>

Hi Shah,  
Please try to run " knife ssl fetch " from the workstation you are bootstrapping new nodes from. So that it has certificates needed for communicating to Chef server. Once workstation has certificates it will send them to newly bootstrapped nodes during bootstrap process as well. And you should not have ssl connection issue anymore.  
More details in regards to this you can find here: [https://docs.chef.io/knife\_ssl\_fetch.html](https://docs.chef.io/knife_ssl_fetch.html)

Or you can just turn off ssl check in client.rb on newly bootstrapped node by adding line as follow: ssl\_verify\_mode :verify\_none

More info on client.rb options you will find here: [http://docs.chef.io/config\_rb\_client.html](http://docs.chef.io/config_rb_client.html)

And just re-run chef-client on bootstrapped node side. From mmy point more preferable and secure is to create and fetch certificates.  
Hopefuly you will find my advises helpful. 🙂  
Regards, Taras.  
— Оригінальне повідомлення —  
Від кого: “Nikhil Shah” [nshah@theorchard.com](mailto:nshah@theorchard.com)  
Дата: 6 серпня 2015, 20:03:32

Hey guys,  
It’s been a while since i started bootstrapping windows machines since I’ve been doing linux for so long, I’ve enabled winrm and setup the proper configs for winrm. However, I am getting the following error and was hoping someone can lead me to the right place:

## eset-era01.theorchard.local C:\Users\Administrator\>chef-client -c c:/chef/client.rb -j c:/chef/first-boot.json -E DEVELOPMENT eset-era01.theorchard.local [2015-08-06T12:44:45-04:00] INFO: \*\*\* Chef 12.4.1 \*\*\* eset-era01.theorchard.local [2015-08-06T12:44:45-04:00] INFO: Chef-client pid: 4104 eset-era01.theorchard.local [2015-08-06T12:45:18-04:00] INFO: Client key c:/chef/client.pem is not present - registering eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: SSL Validation failure connecting to host: chef01.theorchard.local - SSL\_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed eset-era01.theorchard.local eset-era01.theorchard.local ================================================================================ eset-era01.theorchard.local Chef encountered an error attempting to create the client "eset-era01.TheOrchard.local" eset-era01.theorchard.local ================================================================================ eset-era01.theorchard.local eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: Running exception handlers eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: Exception handlers complete eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] FATAL: Stacktrace dumped to c:/chef/cache/chef-stacktrace.out eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] FATAL: OpenSSL::SSL::SSLError: SSL\_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed

Nikhil Shah • System Administrator [nshah@theorchard.com](mailto:nshah@theorchard.com) • p. (+1) 212 308-5648  
THE ORCHARD Distribution Done Right 23 E 4 th St Fl 3, New York, NY 10003 [www.theorchard.com](http://www.theorchard.com)  
Follow us: The Daily Rind • Facebook • Twitter • YouTube • LinkedIn  
Privileged And Confidential Communication. This electronic transmission, and any documents attached hereto, (a) are protected by the Electronic Communications Privacy Act (18 USC §§ 2510-2521), (b) may contain confidential and/or legally privileged information, and © are for the sole use of the intended recipient named above. If you have received this electronic message in error, please notify the sender and delete the electronic message. Any disclosure, copying, distribution, or use of the contents of the information received in error is strictly prohibited.

---

<div class="post-metadata">

**Author:** ![jdunn](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/jdunn/32/1800_2.png) [@jdunn](https://discourse.chef.io/u/jdunn)\
**Post date:** [August 6, 2015, 8:17pm UTC](https://discourse.chef.io/t/winrm/6859/3 "2015-08-06T20:17:11Z")

</div>

That doesn't look like anything to do with WinRM, but that the Chef  
client doesn't trust the SSL certificate being presented by your Chef  
Server "chef01.theorchard.local".

- Julian

On Thu, Aug 6, 2015 at 1:02 PM, Nikhil Shah [nshah@theorchard.com](mailto:nshah@theorchard.com) wrote:

> Hey guys,
> 
> It's been a while since i started bootstrapping windows machines since I've  
> been doing linux for so long, I've enabled winrm and setup the proper  
> configs for winrm. However, I am getting the following error and was hoping  
> someone can lead me to the right place:
> 
> > # eset-era01.theorchard.local C:\Users\Administrator\>chef-client -c c:/chef/client.rb -j c:/chef/first-boot.json -E DEVELOPMENT eset-era01.theorchard.local [2015-08-06T12:44:45-04:00] INFO: \*\*\* Chef 12.4.1 \*\*\* eset-era01.theorchard.local [2015-08-06T12:44:45-04:00] INFO: Chef-client pid: 4104 eset-era01.theorchard.local [2015-08-06T12:45:18-04:00] INFO: Client key c:/chef/client.pem is not present - registering eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: SSL Validation failure connecting to host: chef01.theorchard.local - SSL\_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed eset-era01.theorchard.local eset-era01.theorchard.local
> > 
> > # eset-era01.theorchard.local Chef encountered an error attempting to create the client "eset-era01.TheOrchard.local" eset-era01.theorchard.local
> > 
> > eset-era01.theorchard.local  
> > eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: Running  
> > exception handlers  
> > eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: Exception  
> > handlers complete  
> > eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] FATAL: Stacktrace  
> > dumped to c:/chef/cache/chef-stacktrace.out  
> > eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] FATAL:  
> > OpenSSL::SSL::SSLError: SSL\_connect returned=1 errno=0 state=SSLv3 read  
> > server certificate B: certificate verify failed
> 
> --  
> Nikhil Shah • System Administrator  
> [nshah@theorchard.com](mailto:nshah@theorchard.com) • p. (+1) 212 308-5648
> 
> THE ORCHARD Distribution Done Right  
> 23 E 4th St Fl 3, New York, NY 10003  
> [www.theorchard.com](http://www.theorchard.com)
> 
> Follow us: The Daily Rind • Facebook • Twitter • YouTube • LinkedIn
> 
> Privileged And Confidential Communication. This electronic transmission, and  
> any documents attached hereto, (a) are protected by the Electronic  
> Communications Privacy Act (18 USC §§ 2510-2521), (b) may contain  
> confidential and/or legally privileged information, and (c) are for the sole  
> use of the intended recipient named above. If you have received this  
> electronic message in error, please notify the sender and delete the  
> electronic message. Any disclosure, copying, distribution, or use of the  
> contents of the information received in error is strictly prohibited.

--  
[Julian C. Dunn [jdunn@aquezada.com](mailto:jdunn@aquezada.com) \* Sorry, I'm ]  
[WWW: [http://www.aquezada.com/staff/julian](http://www.aquezada.com/staff/julian) \* only Web 1.0 ]  
[gopher://sdf.org/1/users/keymaker/ \* compliant!]  
[PGP: 91B3 7A9D 683C 7C16 715F 442C 6065 D533 FDC2 05B9]

---

<div class="post-metadata">

**Author:** ![Taras\_Klym](https://avatars.discourse-cdn.com/v4/letter/t/f08c70/32.png) [@Taras\_Klym](https://discourse.chef.io/u/Taras_Klym)\
**Post date:** [August 6, 2015, 8:24pm UTC](https://discourse.chef.io/t/winrm/6859/4 "2015-08-06T20:24:44Z")

</div>

Totally agree with Julian. 🙂  
Either "knife ssl fetch" and re-run chef-client from bootsrtapped node. Or edit/add client.rb and re-run chef-client as well: ssl\_verify\_mode :verify\_none

Regards, Taras.  
--- Оригінальне повідомлення ---  
Від кого: "Julian C. Dunn" [jdunn@aquezada.com](mailto:jdunn@aquezada.com)  
Дата: 6 серпня 2015, 23:19:12

That doesn't look like anything to do with WinRM, but that the Chef  
client doesn't trust the SSL certificate being presented by your Chef  
Server "chef01.theorchard.local".

- Julian

On Thu, Aug 6, 2015 at 1:02 PM, Nikhil Shah \< [nshah@theorchard.com](mailto:nshah@theorchard.com) \> wrote:

> Hey guys,
> 
> It's been a while since i started bootstrapping windows machines since I've  
> been doing linux for so long, I've enabled winrm and setup the proper  
> configs for winrm. However, I am getting the following error and was hoping  
> someone can lead me to the right place:
> 
> > # eset-era01.theorchard.local C:\Users\Administrator\>chef-client -c c:/chef/client.rb -j c:/chef/first-boot.json -E DEVELOPMENT eset-era01.theorchard.local [2015-08-06T12:44:45-04:00] INFO: \*\*\* Chef 12.4.1 \*\*\* eset-era01.theorchard.local [2015-08-06T12:44:45-04:00] INFO: Chef-client pid: 4104 eset-era01.theorchard.local [2015-08-06T12:45:18-04:00] INFO: Client key c:/chef/client.pem is not present - registering eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: SSL Validation failure connecting to host: chef01.theorchard.local - SSL\_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed eset-era01.theorchard.local eset-era01.theorchard.local
> > 
> > # eset-era01.theorchard.local Chef encountered an error attempting to create the client "eset-era01.TheOrchard.local" eset-era01.theorchard.local
> > 
> > eset-era01.theorchard.local  
> > eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: Running  
> > exception handlers  
> > eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] ERROR: Exception  
> > handlers complete  
> > eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] FATAL: Stacktrace  
> > dumped to c:/chef/cache/chef-stacktrace.out  
> > eset-era01.theorchard.local [2015-08-06T12:45:19-04:00] FATAL:  
> > OpenSSL::SSL::SSLError: SSL\_connect returned=1 errno=0 state=SSLv3 read  
> > server certificate B: certificate verify failed
> 
> --  
> Nikhil Shah • System Administrator  
> [nshah@theorchard.com](mailto:nshah@theorchard.com) • p. (+1) 212 308-5648
> 
> THE ORCHARD Distribution Done Right  
> 23 E 4th St Fl 3, New York, NY 10003  
> [www.theorchard.com](http://www.theorchard.com)
> 
> Follow us: The Daily Rind • Facebook • Twitter • YouTube • LinkedIn
> 
> Privileged And Confidential Communication. This electronic transmission, and  
> any documents attached hereto, (a) are protected by the Electronic  
> Communications Privacy Act (18 USC §§ 2510-2521), (b) may contain  
> confidential and/or legally privileged information, and (c) are for the sole  
> use of the intended recipient named above. If you have received this  
> electronic message in error, please notify the sender and delete the  
> electronic message. Any disclosure, copying, distribution, or use of the  
> contents of the information received in error is strictly prohibited.

--  
[Julian C. Dunn \< [jdunn@aquezada.com](mailto:jdunn@aquezada.com) \> \* Sorry, I'm ]  
[WWW: [http://www.aquezada.com/staff/julian](http://www.aquezada.com/staff/julian) \* only Web 1.0 ]  
[gopher://sdf.org/1/users/keymaker/ \* compliant!]  
[PGP: 91B3 7A9D 683C 7C16 715F 442C 6065 D533 FDC2 05B9]

---

<div class="post-metadata">

**Author:** ![Nikhil\_Shah](https://avatars.discourse-cdn.com/v4/letter/n/f17d59/32.png) [@Nikhil\_Shah](https://discourse.chef.io/u/Nikhil_Shah)\
**Post date:** [February 1, 2016, 10:44pm UTC](https://discourse.chef.io/t/winrm/6859/5 "2016-02-01T22:44:20Z")

</div>

Tried to run knife ssl fetch, but got the following error. There isn’t anything block (e.g firewall, iptalbes,etc):

OpenSSL Configuration:

- Version: OpenSSL 1.0.1l 15 Jan 2015
- Certificate file: C:/projects/openssl/knap-build/var/knapsack/software/x86-win  
dows/openssl/1.0.1q/ssl/cert.pem
- Certificate directory: C:/projects/openssl/knap-build/var/knapsack/software/x8  
6-windows/openssl/1.0.1q/ssl/certs  
Chef SSL Configuration:
- ssl\_ca\_path: nil
- ssl\_ca\_file: “C:/opscode/chef/embedded/ssl/certs/cacert.pem”
- trusted\_certs\_dir: “C:/Users/codegenagent\.chef\trusted\_certs”

TO FIX THIS ERROR:

If the server you are connecting to uses a self-signed certificate, you must  
configure chef to trust that server’s certificate.

By default, the certificate is stored in the following location on the host  
where your chef-server runs:

/var/opt/opscode/nginx/ca/SERVER\_HOSTNAME.crt

Copy that file to your trusted\_certs\_dir (currently: C:/Users/codegenagent.chef  
\trusted\_certs)  
using SSH/SCP or some other secure method, then re-run this command to confirm  
that the server’s certificate is now trusted.

C:\Windows\system32\>knife ssl fetch  
WARNING: No knife configuration file found  
WARNING: Certificates from localhost will be fetched and placed in your trusted\_  
cert  
directory (C:/Users/codegenagent.chef\trusted\_certs).

Knife has no means to verify these are the correct certificates. You should  
verify the authenticity of these certificates after downloading.

ERROR: Network Error: No connection could be made because the target machine act  
ively refused it. - connect(2)  
Check your knife configuration and network settings

---

<div class="post-metadata">

**Author:** ![Nikhil\_Shah](https://avatars.discourse-cdn.com/v4/letter/n/f17d59/32.png) [@Nikhil\_Shah](https://discourse.chef.io/u/Nikhil_Shah)\
**Post date:** [February 1, 2016, 10:52pm UTC](https://discourse.chef.io/t/winrm/6859/6 "2016-02-01T22:52:24Z")

</div>

ok i see what i was doing wrong as far as the fetch part… So i was able to fetch the SSL cert:

C:\Windows\system32\>knife ssl check [https://chef01.theorchard.local](https://chef01.theorchard.local)  
WARNING: No knife configuration file found  
Connecting to host chef01.theorchard.local:443  
Successfully verified certificates from `chef01.theorchard.local’

C:\Windows\system32\>

However, when i run chef-client on the node, it still throws that ssl cannot be verified error. Also, why aren’t the certs being shipped to the node.
