Delegating with Kerberos and host headers

From: Stig Johansen (anonymous_at_discussions.microsoft.com)
Date: 02/26/04


Date: Thu, 26 Feb 2004 05:55:52 -0800

We have two Web servers, w1.domain and w2.domain, that now
both have been set up successfully to use Kerberos
authentication. This also works with a common host header
name, c1.domain, for the both these servers. This was
resolved by using the setspn utility to add HTTP/c1.domain
for both the Web servers to AD.

An ASP.NET application running on both these servers uses
delegation (w1 and w2 set to Trust to delegate in AD) to
open a folder structure on a third server. This works fine
if you connect to w1.domain/app or w2.domain/app.

But it does still fail to delegate using the host header
name. So connecting with c1.domain/app fails with an
access denied error on the remote server.

Any ideas why delegation does not work here?

Thx,
Stig



Relevant Pages

  • Re: RDNS LOOPING
    ... Are these you two name servers? ... the delegation, and if you don't see an improvement, you simply just remove ... is how most reverse delegations work. ... 174419 - HOWTO Configure a Subnetted Reverse Lookup Zone on Windows NT, ...
    (microsoft.public.windows.server.dns)
  • Re: RDNS LOOPING
    ... >> servers properly refers to my DNS for a reverse lookup and the other ... > I assume this is a straight delegation instead of a Cname delegation, ... > is how most reverse delegations work. ... > 174419 - HOWTO Configure a Subnetted Reverse Lookup Zone on Windows NT, ...
    (microsoft.public.windows.server.dns)
  • RE: accessing WebService from asp.net App on load balanced Servers
    ... for intranet application within a windows domain ... For general info on ASP.NET delegation: ... Servers ... | | Subject: RE: accessing WebService from asp.net App on load balanced ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: IMPACT of (Delegation Control of Group Policy) on Active Directory
    ... directory that could result from delegating control of group policy ... who is only responsible for desktops and laptops (SUPPORT Engineer). ... Exchange, and other print, share and application servers. ... Engineer has delegation of control to create group policies and link them ...
    (microsoft.public.windows.server.active_directory)
  • Re: IMPACT of (Delegation Control of Group Policy) on Active Direc
    ... directory that could result from delegating control of group policy ... who is only responsible for desktops and laptops (SUPPORT Engineer). ... Exchange, and other print, share and application servers. ... Engineer has delegation of control to create group policies and link them ...
    (microsoft.public.windows.server.active_directory)