WinRM requires ssl

When finding winrm that will not authenticate with NTLM or kerberos and a CA is active you may be able to request a user cert and use that to authenticate.

Also if you can get access to cert templates that allow supplying the subject alternative and changing the useage policy you can get a cert in this manner for any principal i think