Sign in
The Microsoft ProClarity Team Blog
Options
Blog Home
Email Blog Author
Share this
RSS for posts
Atom
RSS for comments
Search Blogs
Tags
64bit
64-bit
Analytics
cannot
code
cube
Dashboard
delegation
Desktop
domain
download
error
exceeded
export to excel
external
kerberos
Migration
pas
ProClarity
Professional
Server
ssas
whitepaper
x64
x86
Archive
Archives
September 2011
(1)
July 2011
(1)
June 2011
(1)
May 2011
(2)
April 2011
(2)
March 2011
(2)
January 2011
(1)
October 2010
(5)
July 2010
(1)
April 2010
(1)
February 2010
(3)
December 2009
(2)
October 2009
(1)
August 2009
(2)
June 2009
(3)
April 2009
(2)
February 2009
(3)
December 2008
(5)
November 2008
(2)
September 2008
(2)
August 2008
(5)
June 2008
(4)
May 2008
(5)
April 2008
(1)
March 2008
(2)
ProClarity and Kerberos Delegation
TechNet Blogs
>
The Microsoft ProClarity Team Blog
>
ProClarity and Kerberos Delegation
ProClarity and Kerberos Delegation
Joey B. Pruett
23 Jun 2011 11:49 AM
Comments
1
Here's another small update to the ProClarity and Kerberos Delegation document.
Kerberos delegation will work with a disjointed domain namespace where the NETBIOS short name does not match the Fully Qualified Domain Name (FQDN). For example, if your FQDN is northamerica.contoso.com and your NETBIOS name is NA.
When using a service account for the application pool in Server 2008 and later, you will need to set useAppPoolCredentials to True on the PAS virtual directory. If useKernelMode is set to True and useAppPoolCredentials is set to False, then Kerberos service ticket decryption fails and you will be prompted for credentials and unable to authenticate. Alternatively, you can disable kernel mode authentication, but this is not recommended.
Use Network Monitor to capture a client’s failed attempt to authenticate to PAS and see data. Filter the traffic by, “HTTP or KerberosV5” and you should see HTTP:Request, HTTP:Response for GET /pas. Find the KerberosV5:TGS Request and Response and you should see the Sname being requested. This is the exact SPN that needs registered on the PAS IIS application pool service account. For example, Sname: HTTP/ProClarityServer.northamerica.contoso.com.
-Joey
Attachment:
ProClarity and Kerberos Delegation.docx
1 Comments
delegation
,
kerberos
,
trust
,
forest
,
external
,
domain
Comments
Comments
Loading...
Leave a Comment
Name
Comment
Please add 1 and 1 and type the answer here:
Post