Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2255
Kerberos delegation with machine alias
Kerberos delegation with machine alias

Kerberos delegation with machine alias

Secure Home | Search | About

Microsoft Applications Security - Microsoft's general security discussions and announcements 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Kerberos delegation with machine alias Cam 10-18-2007
Posted by =?Utf-8?B?Q2Ft?= on October 18, 2007, 5:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
machineA.localnetwork.com - Server 2003 running MS SQL Server
machineB.localnetwork.com - Server 2003 running IIS and SQL Server Reporting
Services and connecting to SQL Server on machineA
machineC.localnetwork.com - XP running IE and connecting to IIS on machineB

Thanks to the "Troubleshooting Kerberos Delegation" whitepaper, everything
is working correctly. I just have one more problem I hope is minor to solve.

Now, I would like to assign an alias to machineB so we can always connect
using the same address (in case one day reporting services is moved to
another machine), such as "reports.localnetwork.com".

In DNS, I created a CNAME called "reports.localnetwork.com" which points to
"machineB.localnetwork.com". When "machineC.localnetwork.com" connects to
"machineB.localnetwork.com", IE prompts for a password. When the domain
user's is entered, the Reporting Services home page is displayed. However,
when any reports are run, this message is displayed:
Login failed for user '(null)'. Reason: Not associated with a trusted SQL
Server connection.

I also turned on DisableStrictNameChecking on machineB and restarted it as
described in KB 281308. This did not help.

Posted by Brian Komar on October 18, 2007, 8:57 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Did you register the Service Principal Name "HOST/reports.localnetwork.com"
at machineB.localnetwork.com?
setspn -a HOST/HOST/reports.localnetwork.com Domain\machineb
Brian

> machineA.localnetwork.com - Server 2003 running MS SQL Server
> machineB.localnetwork.com - Server 2003 running IIS and SQL Server
> Reporting
> Services and connecting to SQL Server on machineA
> machineC.localnetwork.com - XP running IE and connecting to IIS on
> machineB
>
> Thanks to the "Troubleshooting Kerberos Delegation" whitepaper, everything
> is working correctly. I just have one more problem I hope is minor to
> solve.
>
> Now, I would like to assign an alias to machineB so we can always connect
> using the same address (in case one day reporting services is moved to
> another machine), such as "reports.localnetwork.com".
>
> In DNS, I created a CNAME called "reports.localnetwork.com" which points
> to
> "machineB.localnetwork.com". When "machineC.localnetwork.com" connects to
> "machineB.localnetwork.com", IE prompts for a password. When the domain
> user's is entered, the Reporting Services home page is displayed. However,
> when any reports are run, this message is displayed:
> Login failed for user '(null)'. Reason: Not associated with a trusted SQL
> Server connection.
>
> I also turned on DisableStrictNameChecking on machineB and restarted it as
> described in KB 281308. This did not help.


Posted by =?Utf-8?B?Q2Ft?= on October 23, 2007, 5:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Did you register the Service Principal Name "HOST/reports.localnetwork.com"
> at machineB.localnetwork.com?
> setspn -a HOST/HOST/reports.localnetwork.com Domain\machineb
> Brian

Thanks for the hint. After registering the SPN, I can now run the reports.

However, when I point IE to "reports.localnetwork.com", IE still prompts for
a password, whereas pointing IE to machineB.localnetwork.com does not prompt
for password. Is there a minor detail to work out?

Similar ThreadsPosted
Kerberos Delegation July 6, 2005, 2:06 pm
SSPI Kerberos for delegation December 18, 2008, 11:17 am
Using delegation to grant dc event log access June 16, 2005, 4:57 pm
EFS file sharing with constrained delegation June 18, 2009, 4:35 am
2 Questions re: Delegation of Control in Active Directory December 19, 2006, 4:10 pm
RPC on local machine April 1, 2009, 7:01 am
Kerberos UDP vs TCP November 14, 2006, 4:18 am
WHY SOME MACHINE HAVE SP2 AND HAVE POLICY WSUS November 29, 2005, 4:05 pm
Security within Virtual Machine December 5, 2005, 6:16 am
Machine and User credentials October 9, 2006, 5:10 pm

The site map in XML format XML site map

Contact Us | Privacy Policy