L
Laurence
Hi,
I have been pulling my hair out for ages on this one, so please help.
I am trying to connect to a SQL server throu IIS using impersonation.
I am sure I have done 99% of what is needed to do this and still can not get
it to work.
So what have I done.
I have a pure 2003 domain
I have DNS configured and working (as far as I can see correctly)
I have set all the computers to be able to delegat
I have set all the computer accounts to be able to delegate
I have a web site based in windows sharepoint services that works quite
happily when only doing a single hop.
However when I try to do a double hop I get the dreaded 'Login failed for
user (null)' - imlpying its a double hop issue.
I have set SPN's (I think) for all services and users.
However when using the Microsoft AuthDiag diagnostic tool, I get an error
saying 'Service prinsipal name (SPN) for user 'MyDomain\MyUser' not found
inactive directory'
I have sorted all other imperonation error messages but not this one.
If I look at the 'MyDomain\MyUser' using ADSI edit the servicePrincipalName
field contains
HOST/MyUser
HOST/MyUser.MyDomain
HTTP/MyIISMachine.MyDomain.co.uk
So is it that
1). The SPN is wrong - if so what should it be
2). The spn is correct and the diag too is reporting a different error?
I have been pulling my hair out for ages on this one, so please help.
I am trying to connect to a SQL server throu IIS using impersonation.
I am sure I have done 99% of what is needed to do this and still can not get
it to work.
So what have I done.
I have a pure 2003 domain
I have DNS configured and working (as far as I can see correctly)
I have set all the computers to be able to delegat
I have set all the computer accounts to be able to delegate
I have a web site based in windows sharepoint services that works quite
happily when only doing a single hop.
However when I try to do a double hop I get the dreaded 'Login failed for
user (null)' - imlpying its a double hop issue.
I have set SPN's (I think) for all services and users.
However when using the Microsoft AuthDiag diagnostic tool, I get an error
saying 'Service prinsipal name (SPN) for user 'MyDomain\MyUser' not found
inactive directory'
I have sorted all other imperonation error messages but not this one.
If I look at the 'MyDomain\MyUser' using ADSI edit the servicePrincipalName
field contains
HOST/MyUser
HOST/MyUser.MyDomain
HTTP/MyIISMachine.MyDomain.co.uk
So is it that
1). The SPN is wrong - if so what should it be
2). The spn is correct and the diag too is reporting a different error?