SETSPN breaks access to IIS web site



I'm sure I posted to this group yesterday but now can't see the
posting.

I used SETSPN to create a servicePrincipalName for the account I'm
using to run a web site. When I did this, IE could access the page
but VS2005 demanded but then refused to accept credentials when I
tried to open the site.

To confirm that SETSPN was the problem, I deleted the SPN using SETSPN
and the problem went back to the original problem: IE demanded but
then refused to accept credentials, VS2005 could open the web site.

Adding the SPN back went back to IE being able to access the page and
VS2005 not being able to open the website.

So, SETSPN is definitely causing the problem.

A further bit of poking around revealed that a local account on the
IIS server, which was a member of Administrators on the server, could
access the page through IE (when the SPN was deleted) and could open
the web with VS2005 (when the SPN was added).

Something about using an SPN changes network account access to the
server.

Can anyone help, please?

.



Relevant Pages

  • Re: Ldap Binding + Kerbros error
    ... I was suggesting to perform an LDAP query using the exact filter a specified ... A servicePrincipalName (SPN) is the Kerberos name of a service on the ... server authenticates with the client. ... account that is used to execute the Windows process that "is" the service. ...
    (microsoft.public.windows.server.active_directory)
  • Re: SuperSocket Error 19011
    ... usually if you use domain administrator account ... as SQL Server service account, it can register the SPN successfully. ... should use DsWriteAccountSpn API call to register the SPN with Active ...
    (microsoft.public.sqlserver.security)
  • Re: Delegation problems
    ... The connection string uses a variable defined in the web.config. ... the SPN you have on the service account? ... delegate from my web server to the SQL service on the DB server when I ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Delegation problems
    ... This sounds like an SPN problem. ... as a service account, did you add an SPN to that service account in AD that ... delegate from my web server to the SQL service on the DB server when I ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Delegation problems
    ... There are no SPNs on the machine account. ... did you add an SPN to that service account in AD ... delegate from my web server to the SQL service on the DB server when I ...
    (microsoft.public.dotnet.framework.aspnet.security)