all groups > iis security > october 2005 >
You're in the

iis security

group:

IIS Kerberos/SPN Help


IIS Kerberos/SPN Help Craig Taylor
10/27/2005 12:00:00 AM
iis security:
We have an IIS Webserver running on Windows 2000 as part of our domain. Its
netbios/dns name is webserver nad I can connect through a browser to this
address and authenticate using Kerberos OK.
However I have set up an dns alias intranet.theforwardgroup.com to point to
this server but it fails to authenticate. I have followed instruction in KB
326985 Troubleshooting Kerberos_Related Issues in IIS and set up an SPN etc,
but still doesn't work.

Any ideas?

Thanks
Craig
Re: IIS Kerberos/SPN Help Ken Schaefer
10/27/2005 12:00:00 AM
Did you add the FQDN to IE's Intranet security zone?

Cheers
Ken


[quoted text, click to view]
: We have an IIS Webserver running on Windows 2000 as part of our domain.
Its
: netbios/dns name is webserver nad I can connect through a browser to this
: address and authenticate using Kerberos OK.
: However I have set up an dns alias intranet.theforwardgroup.com to point
to
: this server but it fails to authenticate. I have followed instruction in
KB
: 326985 Troubleshooting Kerberos_Related Issues in IIS and set up an SPN
etc,
: but still doesn't work.
:
: Any ideas?
:
: Thanks
: Craig
:

Re: IIS Kerberos/SPN Help Craig Taylor
10/27/2005 12:00:00 AM
Sorry forgot to mention, this is using Safari on OSX which doesn't have
equivalent setiings



On 27/10/05 1:55 pm, in article OLH1EXv2FHA.3272@TK2MSFTNGP09.phx.gbl, "Ken
[quoted text, click to view]

Re: IIS Kerberos/SPN Help Ken Schaefer
10/27/2005 12:00:00 AM
What tickets does the client have? (I'm not sure what the equivalent to
kerbtray is on MacOSX)

Cheers
Ken


[quoted text, click to view]
: Sorry forgot to mention, this is using Safari on OSX which doesn't have
: equivalent setiings
:
:
:
: On 27/10/05 1:55 pm, in article OLH1EXv2FHA.3272@TK2MSFTNGP09.phx.gbl,
"Ken
[quoted text, click to view]
:
: > Did you add the FQDN to IE's Intranet security zone?
: >
: > Cheers
: > Ken
: >
: >
[quoted text, click to view]
: > : We have an IIS Webserver running on Windows 2000 as part of our
domain.
: > Its
: > : netbios/dns name is webserver nad I can connect through a browser to
this
: > : address and authenticate using Kerberos OK.
: > : However I have set up an dns alias intranet.theforwardgroup.com to
point
: > to
: > : this server but it fails to authenticate. I have followed instruction
in
: > KB
: > : 326985 Troubleshooting Kerberos_Related Issues in IIS and set up an
SPN
: > etc,
: > : but still doesn't work.
: > :
: > : Any ideas?
: > :
: > : Thanks
: > : Craig
: > :
: >
: >
:
:

Re: IIS Kerberos/SPN Help Craig Taylor
10/31/2005 12:00:00 AM
The client gets the ticket for webserver@theforwardgroup.com which is the
netbios/dns name, but it doesn't get a ticket against any alias set up as
SPNs

Thanks
Craig


On 28/10/05 2:28 am, in article e3Sced22FHA.268@TK2MSFTNGP10.phx.gbl, "Ken
[quoted text, click to view]

Re: IIS Kerberos/SPN Help Ken Schaefer
10/31/2005 12:00:00 AM
Hi,

Can i get some more configuration information please?

Is the DNS alias that you created pointing to an existing site (i.e. a site
that can be accessed via http://servername)? or to a separate site?

The web app pool that the site is running under - is it Localsystem or
Network Service? or a custom user account that you've created?

Lastly, what's the output when you list the SPNs for the machine account?

Thanks

Cheers
Ken


[quoted text, click to view]
: The client gets the ticket for webserver@theforwardgroup.com which is the
: netbios/dns name, but it doesn't get a ticket against any alias set up as
: SPNs
:
: Thanks
: Craig
:
:
: On 28/10/05 2:28 am, in article e3Sced22FHA.268@TK2MSFTNGP10.phx.gbl, "Ken
[quoted text, click to view]
:
: > What tickets does the client have? (I'm not sure what the equivalent to
: > kerbtray is on MacOSX)
: >
: > Cheers
: > Ken
: >
: >
[quoted text, click to view]
: > : Sorry forgot to mention, this is using Safari on OSX which doesn't
have
: > : equivalent setiings
: > :
: > :
: > :
: > : On 27/10/05 1:55 pm, in article OLH1EXv2FHA.3272@TK2MSFTNGP09.phx.gbl,
: > "Ken
[quoted text, click to view]
: > :
: > : > Did you add the FQDN to IE's Intranet security zone?
: > : >
: > : > Cheers
: > : > Ken
: > : >
: > : >
[quoted text, click to view]
: > : > : We have an IIS Webserver running on Windows 2000 as part of our
: > domain.
: > : > Its
: > : > : netbios/dns name is webserver nad I can connect through a browser
to
: > this
: > : > : address and authenticate using Kerberos OK.
: > : > : However I have set up an dns alias intranet.theforwardgroup.com to
: > point
: > : > to
: > : > : this server but it fails to authenticate. I have followed
instruction
: > in
: > : > KB
: > : > : 326985 Troubleshooting Kerberos_Related Issues in IIS and set up
an
: > SPN
: > : > etc,
: > : > : but still doesn't work.
: > : > :
: > : > : Any ideas?
: > : > :
: > : > : Thanks
: > : > : Craig
: > : > :
: > : >
: > : >
: > :
: > :
: >
: >
:
:

Re: IIS Kerberos/SPN Help Craig Taylor
11/1/2005 10:50:53 AM
Hi Ken
I have 3 separate sites that I am trying to set up:
webserver.theforwardgroup.com which points to a site called internal
dev.theforwardgroup.com which points to a site called external
testintranet.theforwardgroup.com which points to a site called testintranet

Only webserver site works because this is the dns/netbios name of server.
The other two are aliases pointing to separate sites. IIS is running as
Localsystem

Here is the setspn output
C:\Program Files\Resource Kit>setspn -l webserver

Registered ServicePrincipalNames for
CN=WEBSERVER,OU=Servers,DC=theforwardgroup,

DC=com:

HOST/testintranet

HOST/dev

HOST/dev.theforwardgroup.com

HOST/testintranet.theforwardgroup.com

SMTPSVC/WEBSERVER

SMTPSVC/webserver.theforwardgroup.com

HOST/WEBSERVER

HOST/webserver.theforwardgroup.com

Thanks for your help
Craig





On 1/11/05 1:47 am, in article ue#$GZo3FHA.268@TK2MSFTNGP10.phx.gbl, "Ken
[quoted text, click to view]

Re: IIS Kerberos/SPN Help Ken Schaefer
11/2/2005 12:00:00 AM
Hi there,

IIS is running as LocalSystem, but the actual web application pools that
your websites are hosted in - what are they running under? The SPNs need to
be registered under the correct machine or user account in AD. And this
needs to be the account assigned to the web application pool.

Since all these machines are in the same domain, I'm going to assume that
the MacOSX knows where to go to get the tickets from...

Cheers
Ken


[quoted text, click to view]
: Hi Ken
: I have 3 separate sites that I am trying to set up:
: webserver.theforwardgroup.com which points to a site called internal
: dev.theforwardgroup.com which points to a site called external
: testintranet.theforwardgroup.com which points to a site called
testintranet
:
: Only webserver site works because this is the dns/netbios name of server.
: The other two are aliases pointing to separate sites. IIS is running as
: Localsystem
:
: Here is the setspn output
: C:\Program Files\Resource Kit>setspn -l webserver
:
: Registered ServicePrincipalNames for
: CN=WEBSERVER,OU=Servers,DC=theforwardgroup,
:
: DC=com:
:
: HOST/testintranet
:
: HOST/dev
:
: HOST/dev.theforwardgroup.com
:
: HOST/testintranet.theforwardgroup.com
:
: SMTPSVC/WEBSERVER
:
: SMTPSVC/webserver.theforwardgroup.com
:
: HOST/WEBSERVER
:
: HOST/webserver.theforwardgroup.com
:
: Thanks for your help
: Craig
:
:
:
:
:
: On 1/11/05 1:47 am, in article ue#$GZo3FHA.268@TK2MSFTNGP10.phx.gbl, "Ken
[quoted text, click to view]
:
: > Hi,
: >
: > Can i get some more configuration information please?
: >
: > Is the DNS alias that you created pointing to an existing site (i.e. a
site
: > that can be accessed via http://servername)? or to a separate site?
: >
: > The web app pool that the site is running under - is it Localsystem or
: > Network Service? or a custom user account that you've created?
: >
: > Lastly, what's the output when you list the SPNs for the machine
account?
: >
: > Thanks
: >
: > Cheers
: > Ken
: >
: >
[quoted text, click to view]
: > : The client gets the ticket for webserver@theforwardgroup.com which is
the
: > : netbios/dns name, but it doesn't get a ticket against any alias set up
as
: > : SPNs
: > :
: > : Thanks
: > : Craig
: > :
: > :
: > : On 28/10/05 2:28 am, in article e3Sced22FHA.268@TK2MSFTNGP10.phx.gbl,
"Ken
[quoted text, click to view]
: > :
: > : > What tickets does the client have? (I'm not sure what the equivalent
to
: > : > kerbtray is on MacOSX)
: > : >
: > : > Cheers
: > : > Ken
: > : >
: > : >
[quoted text, click to view]
: > : > : Sorry forgot to mention, this is using Safari on OSX which doesn't
: > have
: > : > : equivalent setiings
: > : > :
: > : > :
: > : > :
: > : > : On 27/10/05 1:55 pm, in article
OLH1EXv2FHA.3272@TK2MSFTNGP09.phx.gbl,
: > : > "Ken
[quoted text, click to view]
: > : > :
: > : > : > Did you add the FQDN to IE's Intranet security zone?
: > : > : >
: > : > : > Cheers
: > : > : > Ken
: > : > : >
: > : > : >
: > : > : > "Craig Taylor" <craig.taylor@theforwardgroup.com> wrote in
message
: > : > : > news:BF867311.73BA%craig.taylor@theforwardgroup.com...
: > : > : > : We have an IIS Webserver running on Windows 2000 as part of
our
: > : > domain.
: > : > : > Its
: > : > : > : netbios/dns name is webserver nad I can connect through a
browser
: > to
: > : > this
: > : > : > : address and authenticate using Kerberos OK.
: > : > : > : However I have set up an dns alias
intranet.theforwardgroup.com to
: > : > point
: > : > : > to
: > : > : > : this server but it fails to authenticate. I have followed
: > instruction
: > : > in
: > : > : > KB
: > : > : > : 326985 Troubleshooting Kerberos_Related Issues in IIS and set
up
: > an
: > : > SPN
: > : > : > etc,
: > : > : > : but still doesn't work.
: > : > : > :
: > : > : > : Any ideas?
: > : > : > :
: > : > : > : Thanks
: > : > : > : Craig
: > : > : > :
: > : > : >
: > : > : >
: > : > :
: > : > :
: > : >
: > : >
: > :
: > :
: >
: >
:
:

Re: IIS Kerberos/SPN Help Craig Taylor
11/3/2005 12:00:00 AM
Hi Ken
Sorry you have lost me there, how do I find out what and how the web
application pools are running under?

Cheers
Craig

On 2/11/05 11:06 am, in article O77tJ253FHA.3400@tk2msftngp13.phx.gbl, "Ken
[quoted text, click to view]
Re: IIS Kerberos/SPN Help Ken Schaefer
12/7/2005 5:48:43 PM
Sorry to take s long to get back to you, but in case this is still an open
issue:

In the IIS Manager in the Web App Pools node. For each web app pool there is
a place to configure an "identity" for the web app pool. This is the user
account used to run the w3wp.exe process.

Cheers
Ken

[quoted text, click to view]
: Hi Ken
: Sorry you have lost me there, how do I find out what and how the web
: application pools are running under?
:
: Cheers
: Craig
:
: On 2/11/05 11:06 am, in article O77tJ253FHA.3400@tk2msftngp13.phx.gbl,
"Ken
[quoted text, click to view]
:
: > Hi there,
: >
: > IIS is running as LocalSystem, but the actual web application pools that
: > your websites are hosted in - what are they running under? The SPNs need
to
: > be registered under the correct machine or user account in AD. And this
: > needs to be the account assigned to the web application pool.
: >
: > Since all these machines are in the same domain, I'm going to assume
that
: > the MacOSX knows where to go to get the tickets from...
: >
: > Cheers
: > Ken
:

AddThis Social Bookmark Button