Re: Problem with impersonation and using a different host name.



You need to give the machine account an additional service principal name
(SPN) for http/bob.mydomain.com. There is a tool called setspn.exe that
does this. Your domain admin must run it.

That should allow the you to do Kerberos authentication with the different
DNS name. That should in turn allow delegation (assuming both sites use
Network Service as the app pool identity).

Joe K.

"Patrick Meehan" <PatrickMeehan@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:FD903F9F-D1BB-44D9-A462-9F3DF0B60AA1@xxxxxxxxxxxxxxxx
>I have developed a ASP.Net page with VS 2005 and SQL Server 2005. The
>server
> I am using is Windows 2003 and I have set up 2 websites, one production
> and
> one for test and development. This is our corporate intranet server and a
> DNS entry is setup to point 'intranet' to this machine, however, the
> computer
> name is different. Lets call it 'bob'. 'bob' has been trusted for
> delegation.
>
> If I go to http://bob.mydomain.net/mysite it works fine, both in test and
> production. But if I go to http://intranet.mydomain.net/mysite I get
> "Login
> failed for user 'NT AUTHORITY\ANONYMOUS LOGON'.
>
> It seems pretty clear to me that the issue is the different DNS hostname,
> but is there a work around for this?


.



Relevant Pages

  • 2000 to 2003 Domain Migration Scenario question
    ... We currently have 3 Win2k domain controllers, Bob, John and Exchange. ... Bob and Exchange are DNS servers. ... and is also the Global catalog server. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Event ID 1097 and 1030 Errors...
    ... > Is the time Synchronising between all DC's? ... I have the Operations Master server sync'ing with an external ... > Is dns installed on this DC? ... > Is the machine account in AD? ...
    (microsoft.public.windows.server.general)
  • Re: 2000 to 2003 Domain Migration Scenario question
    ... How to reconfigure an _msdcs subdomain to a forest-wide DNS application directory partition when you upgrade from Windows 2000 to Windows Server 2003 ... We currently have 3 Win2k domain controllers, Bob, John and Exchange. ... Bob and Exchange are DNS servers. ...
    (microsoft.public.windows.server.active_directory)
  • Re: server 2003 single nic pptp vpn
    ... posts here by simply pointing to a FAQ or blurb on your website. ... I emailed Bob asking for help, ... IN any case it is obvious that I have a DNS problem... ... information is passed from the server to the client via an initial file ...
    (microsoft.public.windows.server.networking)
  • Re: 2000 to 2003 Domain Migration Scenario question
    ... directory partition when you upgrade from Windows 2000 to Windows Server ... We currently have 3 Win2k domain controllers, Bob, John and Exchange. ... Bob and Exchange are DNS servers. ...
    (microsoft.public.windows.server.active_directory)