Re: kerberos tickets and the SPNs




I use also msktutil and you can find it here http://dag.wieers.com/rpm/packages/msktutil/

You can also use setspn -A host/fqdn in lowercase. instead of setspn -R.

BTW the original netjoin tool from MS used computer accounts not user accounts. http://msdn.microsoft.com/en-us/library/ms808911.aspx
http://download.microsoft.com/download/win2000pro/2kkerb2/1.0/nt5/en-us/ad-unix.exe I don't know why they changed their mind.

Markus

----- Original Message ----- From: "Ravi Channavajhala" <ravi.channavajhala@xxxxxxxxxx>
To: "Douglas E. Engert" <deengert@xxxxxxx>
Cc: "Markus Moeller" <huaraz@xxxxxxxxxxxxxxxx>; <kerberos@xxxxxxx>
Sent: Friday, May 08, 2009 8:59 PM
Subject: Re: kerberos tickets and the SPNs


Don't agree here. Natively adding a computer to AD and checking with
setspn -L didn't show any SPNs. Resetting the SPNs with setspn -R,
creates two entries

HOST/HOSTNAME$
HOST/HOSTNAME$.SHORTFORM DOMAIN

Both are incorrect....

The point is, I can manipulate SPNs to no end, but obviously no
success with Kerberos. My real issue is kerberos flip flopping with
'Server not found in Database' to 'Keytable entry incorrect Key
version'.


.



Relevant Pages

  • Re: kerberos tickets and the SPNs
    ... kerberos tickets and the SPNs ... Resetting the SPNs with setspn -R, ... Argonne National Laboratory ...
    (comp.protocols.kerberos)
  • Re: kerberos tickets and the SPNs
    ... You can also use setspn -A host/fqdn in lowercase. ... BTW the original netjoin tool from MS used computer accounts not user ... kerberos tickets and the SPNs ...
    (comp.protocols.kerberos)
  • Re: SPN for website (with AppPool) running under a Host Header
    ... You can use SetSPN to ensure that the SPNs exist under the ... Test\App Pool Username user account. ... :> Running the K2 website under the networkservice identity works, ...
    (microsoft.public.inetserver.iis.security)
  • Re: Need Help Understanding Kerberos SPN Problem
    ... And so I figure you're probably spending a while troubleshooting this. ... manually, using Setspn. ... with Kerberos in our domain. ... understand SPNs any better after reading those than I did before. ...
    (microsoft.public.windows.server.active_directory)
  • Need Help Understanding Kerberos SPN Problem
    ... I either don't understand how to use SETSPN, or I have some serious problem ... the domain controller are returning errors indicating the account doesn't ... I've read the Microsoft documents on troubleshooting Kerberos, ... understand SPNs any better after reading those than I did before. ...
    (microsoft.public.windows.server.active_directory)