Service Principal Name in Kerberos



Hi,

I have three-tier application, which consists of a client, an application
server and MS SQL server. Client and application server runs under domain
accounts. Also they both use impersonation with Kerberos. Plus, an account
under which application server runs on has 'Account is trusted for
delegation' turned on. So that as a net result MS SQL does authenticate a
user that runs a client. In order to work with Kerberos a client has to
specify Service Principal Name (SPN). In the present moment we do specify
Domain\AppServerUser that runs application server as an SPN.

1) Is that usage of SPN correct, i.e. SPN = Domain\AppServerUser?

2) What do we have to do in order to use SPN in the form, which is used in
case for IIS or Exchange? For example: OurServiceName/host.domain. And does
it actually need in contrast to the case when SPN = Domain\AppServerUser?

Thank you.
--
Andrei.


.



Relevant Pages

  • RE: Cant install Windows Small Business 2003 Client
    ... Make sure that the Small Business Server ... that if the client computer is asking for the user and password is because is ... Try deleting one computer and create a new user account and recreate the ... computer object to see if that account can be use connectcomputer then. ...
    (microsoft.public.windows.server.sbs)
  • Re: Using EFS with Network Shares and SFU 3.5
    ... It does not take EFS into account. ... could again use the sharing server audit logs to see if success ... Read extended attribute and Read data, since the NFS client may ... Windows and *nix clients. ...
    (microsoft.public.windows.server.security)
  • RE: configuring client users
    ... This newsgroup only focuses on SBS technical issues. ... | Thread-Topic: configuring client users ... |> computer to SBS server while we need use "set up computer wizard" to ... |> For user account issue, please understand that if you join the client ...
    (microsoft.public.windows.server.sbs)
  • RE: configuring client users
    ... > Welcome to SBS newsgroup. ... we use "connect computer wizard" to connect the client ... > computer to SBS server while we need use "set up computer wizard" to set up ... > best interest to rerun the wizard again to add the client computer account ...
    (microsoft.public.windows.server.sbs)
  • Re: Ldap Binding + Kerbros error
    ... I was suggesting to perform an LDAP query using the exact filter a specified ... A servicePrincipalName (SPN) is the Kerberos name of a service on the ... server authenticates with the client. ... account that is used to execute the Windows process that "is" the service. ...
    (microsoft.public.windows.server.active_directory)