• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Kerberos - registering an SPN against service account

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    Kerberos - registering an SPN against service account

    Pulling what little hair I have left over getting Kerberos authentication working. There are so many variables at play but I know that one piece of the jigsaw that I have to get working is proving problematic.

    I have a web app that authentiicates users via forms authentication. They are then validated with an active directory membership provider (they proovide a domain qualified windows user id as the forms login)

    and I use impersonation and delegation to access external resources such as other web apps.

    Since the web app (IIS7) runs under the service account I have set up for its app pool, my understanding is that I have to set up an SPN against the app pool account. The web app url is in the form <server>/<appname> so I should set an SPN of HTTP/server/appname against the user. I can do this with setSPN utility but the ticket doesn't appear in Kerbtray for that user and various diagnostic tools tell me It's invalid.

    I think I've followed all the rules for naming conventions so there must be something im missing.

    Any help would be greatly appreciated.

    #2
    Good morning Malcom, is there anyway you can pull any logs from the system? Sometimes they give a clue as to what is going wrong.
    SUFTUM

    May life give you what you need, rather than what you want....

    Comment


      #3
      Originally posted by Netraider View Post
      Good morning Malcom, is there anyway you can pull any logs from the system? Sometimes they give a clue as to what is going wrong.
      Morning NR. I can see from running Wireshark on the 2nd hop server that a Kerberos ticket is passed. No error messages in the logs. I suspect it is passing the wrong ticket as I get 401 errors.

      Comment

      Working...
      X