|
Hey Tony, Well can you explain “but wouldn't you also need an SPN for the web service on the
ISA Server?” I don’t understand why, the ISA server is the server
that is needing the authentication to allow the web server to browse the
internet.
I have a Share Point site it has a RSS
feed web part, this web part is requesting a RSS feed for example http://www.dirteam.com/blogs/carlos/default.aspx
now I monitor on the ISA 2004 server and I see the web server trying to access
the internet the user specified = Anonymous. The delegation is so that the user
viewing the Share Point site (hence calling the RSS web part) will be the user
credentials passed to the ISA server to be able to browse the internet. That’s why I don’t see why we
need to register a SPN for the ISA server? Thanks From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tony Murray Hi Carlos I'm just starting to look at Kerberos
delegation for something myself, but wouldn't you also need an SPN for the
web service on the ISA Server? And then specify that serviced in the
delegation tab on the user object? Cheers Tony From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
Behalf Of Carlos Magalhaes Hey all, Ok late at night here and I’ve hit a mental block
(don’t laugh Dean). I have set this up like a gazillion times but this
time cant get it to work. Environment: Windows 2003 Native Forest Mode – All clients Windows
XP SP2 and above Single forest single domain setup Web Server – Windows Server 2003 Web Edition Share Point Team Services installed. That site has a web part that requires Kerb delegation for
access to a ISA firewall in order to stream RSS feeds. I can see on the ISA
server that when ever any user hits the site the HTTP request is sent as
ANONYMOUS. So what I have done:
a. Purged all
tickets as well.
Still get Anonymous access on the ISA box, and using some
normal .net code can see that its not delegating the creds correctly, can
anyone see what I am doing wrong or what I should be doing?
Carlos This e-mail message has been scanned for Viruses and Content and
cleared by NetIQ MailMarshal at Gen-i
|
- RE: [ActiveDir] Kerberos Delegation Carlos Magalhaes
- RE: [ActiveDir] Kerberos Delegation Tony Murray
- RE: [ActiveDir] Kerberos Delegation Carlos Magalhaes
- RE: [ActiveDir] Kerberos Delegation Roger Seielstad
- RE: [ActiveDir] Kerberos Delegation Ken Schaefer
- RE: [ActiveDir] Kerberos Delegation Carlos Magalhaes
- RE: [ActiveDir] Kerberos Delegation Roger Seielstad
- RE: [ActiveDir] Kerberos Delegation Ken Schaefer
- RE: [ActiveDir] Kerberos Delegation Roger Seielstad
- RE: [ActiveDir] Kerberos Delegation Brian Desmond
- RE: [ActiveDir] Kerberos Delegation Carlos Magalhaes
