Re: Application Pools, Domain User Accounts and Service Principal Names



My experience has been that to have an SPN that belongs to the domain service account that does not conflict with the SPNs already assigned to the machine account, you need a new DNS name and a new A record in DNS for that name. Then, if you give the machine account the SPN corresponding to the new DNS name, should be ok.

This is really out of my league, the documentation I have found is purely technical, and nothing you can learn from. Well, it's back to using .NET impersonation and recording static user credentials in the registry...

I feel your pain. :)

The problem is there is no way I can communicate this to Microsoft and say HOY! the documentation doesn't go nearly far enough, how 'bout improving it! I did sent them feedback for the article but I'm sure that will just go off into oblivion.

Thanks Joe.
.



Relevant Pages

  • Re: Problem with impersonation and using a different host name.
    ... You need to give the machine account an additional service principal name ... DNS name. ... >I have developed a ASP.Net page with VS 2005 and SQL Server 2005. ... Lets call it 'bob'. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: Prompted for Credentials
    ... And it's been on port 80. ... But DNS hasn't changed nor have I modified any entries. ... it would prompt for a password (unless added in the local ... will notice it is actually asking for a machine account ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Problem with impersonation and using a different host name.
    ... If you are going to be using delegation, it pays to learn as much as you can ... >> You need to give the machine account an additional service principal name ... >> DNS name. ... This is our corporate intranet server ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: Slow Logon
    ... Several reasons for this but 90% of the time it's DNS. ... If you are using DHCP or static addresses just make sure the requests are ... > you logon to the machine account it boots right up. ...
    (microsoft.public.windowsxp.general)