WinRM requires ssl
When finding winrm that will not authenticate with NTLM or kerberos and a CA is active you may be able to request a user cert and use that to authenticate.
Also if you can get access to cert templates that allow supplying the subject alternative and changing the useage policy you can get a cert in this manner for any principal i think