IIS Kerberos Authentication issue;



Hello

I have two web applications running in different app pools. First one
[WA1] runs in the default pool [P1-LocalService], and the other [WA2]
in a seperate pool [P2] with identify of a domain account: DA1.

Window integrated authentication is enabled for both;

I access the url using http://IISMachine_NBiosName

Initially I was able to access WA1, but was not able to run WA2. For
WA2 I got the credentials dialog popped thrice before the access
denied error 401.1

Then I set the spns for DA1
HTTP/IISMachine_NBiosName & HTTP/IISMachine_FQDNName.

After this WA2 started working but WA1 stopped working;

I got the following kerberos error in the event log
KRB_AP_ERR_MODIFIED error from the server host/IISMachine_FQDNName.
The targetName used was http/IISMachine_FQDNName. This indicates that
the password used to encrypt the kerberso services ticket is different
than that on the target server. Commonly this is due to identicaly
named machine accounts in the target realm (DomainFQDNName) and the
client realm. Please contact your system administrator;

Is it that we cannot have two web applications using integrated
authentication with different accounts? LocalService & Domain account?

Since the HTTP/IISMachine_NBiosName SPN is set for the user, I assume
this conflicts with the default HOST/IISMachine_NBiosName for the
computer account?

How do I resolve this to get both my applications working? without
making them run in the same pool :)

Regards,
Alwyn
.



Relevant Pages

  • Re: setting incoming email
    ... Going through these steps should update the application pool as well. ... I log into the wss server and then go into IIS manager, within iis manager I go into the application pools and change the identity of the application pool for the site from network service to a domain account(domain admin account for now) in my active directory. ... I changed the app pool for the site and central admin to the same domain account but when I change it from the network service account to the domain account and try to login to the site it prompts me for a login. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: setting incoming email
    ... pool for the site from network service to a domain account(domain admin ... account for now) in my active directory. ... It doesn't even prompt me for a password or login. ... Is there anyway i can assign the app pool an domain account and be able ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: E-Mail-Enabled Document Libraries
    ... I would try it but a better solution may be to create a domain account like ... add it to the local administrators group of the WSS server ... > i need to run the pool using the domain admin account as that has access ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Unable to retreive domain name from Active Directory Services
    ... We are using the a new Domain account we created just for SharePoint. ... application pool also uses this account. ...
    (microsoft.public.sharepoint.portalserver.development)
  • Re: Incoming E-Mail - cant create contact in OU
    ... central admin pool different than the web app. ... that account a little (if the web app is compromised or something, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)