Network Management
SWISPowerShell -Trusted fails locally in the SolarWinds Platform
Connect-Swis -Hostname localhost -Trusted can create a SWIS connection object locally on the main poller, but the first Get-SwisData request fails with System.ServiceModel.Security.SecurityNegotiationException: The server has rejected the client credentials.
First published date
Last published date
Overview
Connect-Swis -Hostname localhost -Trusted can create a SWIS connection object locally on the main poller, but the first Get-SwisData request fails with: "System.ServiceModel.Security.SecurityNegotiationException: The server has rejected the client credentials."
The same -Trusted connection may work from a remote computer.
This behavior is associated with the local WCF Windows authentication path, not with the SWQL query, TCP connectivity, DNS resolution, or the user’s password.
Typical symptoms are:
-
Connect-Swis -Hostname localhost -Trustedappears to succeed. Get-SwisDatafails when it opens the service channel.- The failure occurs on the main poller but the same user can connect remotely.
- The exception is raised during WCF
WindowsStreamSecuritynegotiation. - Port 17777 can be reachable and Kerberos/SPN checks can succeed while the SWIS request still fails.
- Local Administrators and domain accounts can be rejected even when they have full administrative permissions.
The connection object is created lazily. Therefore, a successful Connect-Swis call does not prove that the authenticated SWIS request has completed.
Product section
Cause
The -Trusted path uses a WCF net.tcp binding with Windows Stream Security. In the reproduced local failure, the caller is an interactive or service account with IsSystem = False.
The local SWIS binding rejects that Windows token during the WCF security upgrade and accepts only the NT AUTHORITY\SYSTEM identity for this local path.
Local Administrator membership is not equivalent to NT AUTHORITY\SYSTEM. Consequently, adding the account to Administrators, validating an SPN, obtaining a Kerberos ticket, or confirming that TCP 17777 is open does not change the local binding decision.
The error message is misleading because it says that the server rejected the client credentials, which suggests an incorrect password. The rejection occurs before the SWQL query reaches normal SWIS query processing.
This is a known product limitation/defect in the local -Trusted WCF authentication path. No configuration option is recorded for allowing additional interactive accounts on this binding. The related bug record is currently documented as workaround-only.
Resolution
The Development team is working to add more authentication options like Token and Oauth. Meanwhile, you can use one of the following workarounds:
-
Use explicit SolarWinds Platform credentials for a PowerShell script:
Import-Module SwisPowerShell $server = "localhost" $credential = Get-Credential $swis = Connect-Swis ` -Hostname $server ` -Credential $credential Get-SwisData ` -SwisConnection $swis ` -Query "SELECT TOP 1 Caption FROM Orion.Nodes" -
Run the script from a remote computer and connect to the main poller using
-Trusted:$swis = Connect-Swis ` -Hostname "MAIN-POLLER-FQDN" ` -Trusted -
Use certificate authentication locally, where the SolarWinds certificate configuration supports it:
$swis = Connect-Swis ` -Hostname "localhost" ` -Certificate Get-SwisData ` -SwisConnection $swis ` -Query "SELECT TOP 1 Caption FROM Orion.Nodes"
Do not change the WCF security mode to None, disable Windows security, grant SeTcbPrivilege, or run interactive scripts as SYSTEM solely to bypass this behavior. The related investigation identified those approaches as unsafe or unsuitable as a general resolution.