Kerberos to NTLM delegation timeout



I apologize if this is available but there is so much on getting delegation
getting to work we aren't coming up with anything.

First off we are using constrained delegation to run a dual server
environment for ASP.NET 2.0 application under IIS 6.0 and SQL Server 2005.
All Windows Server 2k3. Our Active Directory is balanced two different
servers.

A subset of our users are receiving delegation errors at what seems like
random, inconsistent times of the day. Most of the time the majority of the
users are working fine.

Basically the Kerberos ticket appears to either expire or be overridden by
an NTLM ticket causing a double hop failure.

We have determined that the problem can temporarily be solved by doing the
following:
Close IE -> Control-Alt-Delete -> Lock -> UnLock

However, one the original problem happens this only seems to fix it for a
short while until the same error is experienced again.

Any direction or ideas at all would be greatly appreciated.

- Marc Castrechini


.



Relevant Pages

  • Re: Constrained delegation question!
    ... remote server running the services in terms of the security audits on the ... AUTHORITY\ANONYMOUS LOGON event. ... you won't be able to get Kerb delegation to ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Unix Bind and Windows DNS coexist problem with forwarder ON
    ... not a web server. ... Here is the MS KB link of how i setup in Microsoft DNS server. ... I setup delegation in UNIX BIND server to Windows 2003 ... >>> The above does not describe delegation. ...
    (microsoft.public.windows.server.dns)
  • Re: Constrained delegation question!
    ... You are right there is a service called HOST on the target server which I ... You should not need to create a new SPN though. ... Active Directory under the delegation tab, ... For allowing Service Control Manager, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Constrained delegation question!
    ... You are right there is a service called HOST on the target server which I ... You should not need to create a new SPN though. ... Active Directory under the delegation tab, ... For allowing Service Control Manager, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: PROBLEM: ASP on IIS 5 secured via "Windows Integrated Authentication" accessing "
    ... I have two virtual directories on same server with Integrated ... If i use basic authentication, ... as .NET framework config file) as well as Delegation as specified by the ... > could do whatever you want in your ASP page on behalf of the Domain Admin. ...
    (microsoft.public.inetserver.iis.security)