Click here to monitor SSC
SQLServerCentral is supported by Red Gate Software Ltd.
 
Log in  ::  Register  ::  Not logged in
 
 
 
        
Home       Members    Calendar    Who's On


Add to briefcase 12345»»»

A brief explanation and solution for the Double Hop problem Expand / Collapse
Author
Message
Posted Thursday, December 8, 2011 10:03 PM


Hall of Fame

Hall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of Fame

Group: General Forum Members
Last Login: Yesterday @ 1:17 PM
Points: 3,467, Visits: 1,840
Comments posted to this topic are about the item A brief explanation and solution for the Double Hop problem

Kenneth Fisher
I strive to live in a world where a chicken can cross the road without being questioned about its motives.
--------------------------------------------------------------------------------
For better, quicker answers on T-SQL questions, click on the following...
http://www.sqlservercentral.com/articles/Best+Practices/61537/
For better answers on performance questions, click on the following...
http://www.sqlservercentral.com/articles/SQLServerCentral/66909/

Link to my Blog Post --> www.SQLStudies.com
Post #1219052
Posted Friday, December 9, 2011 1:39 AM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: General Forum Members
Last Login: Friday, December 9, 2011 1:38 AM
Points: 2, Visits: 0
After the <a href="http://www.ugg6canada.com/ugg-kids-classic-boots-c-4/"><strong>Ugg Kids Classic Boots</strong></a> renovation of the Canada Goose <a href="http://www.i-uggbootssale.net/kids-ugg-boots-c-12.html"><strong>Kids <a href="http://www.suprashoessale-uk.com/nike-shoes-sale-mens-air-max-2003-sale-c-86_92.html"><strong>Air Max 2003</strong></a> <a href="http://www.ugg6canada.com/"><strong>Ugg Boots <a href="http://www.ugg6canada.com/ugg-fox-fur-boots-c-40/"><strong>Ugg Fox Fur Boots</strong></a> Sale</strong></a> Ugg Boots Sale</strong></a> Solaris wife <a href="http://www.canadagoose-coats-sale.com/canada-goose-chateau-parka-c-2.html"><strong>Canada Goose Chateau Parka Online</strong></a> <a href="http://www.suprashoessale-uk.com/nike-shoes-sale-c-86.html"><strong>Nike Shoes Sale</strong></a> looks more youth and sports,Suitable for the urban womenlook great and stay warm. UGG classic tall boots, UGG classic <a href="http://www.i-uggbootssale.net/ugg-amberlee-boots-c-13.html"><strong>UGG Amberlee Boots Sale</strong></a> cardy boots, UGG classic short boots and <a href="http://www.i-uggbootssale.net/"><strong>Ugg Boots Store</strong></a> the style are always Continuously increasing, there will be <a href="http://www.canadagoose-coats-sale.com/canada-goose-banff-parka-c-1.html"><strong>Canada Goose Banff Parka Sale</strong></a> one is you like. All Supra Skytop Shoes - Supra Vaider Shoes - Supra Society Shoes at High Discount & High Quality. Welcome to Buy Supra Shoes in this Supra Shoes Sale season, Buy now! Atlantic Ugg Jimmy Choo Sora Black Boots <a href="http://www.canadagoose-coats-sale.com/"><strong>Canada Goose Coats</strong></a> makes you attractive and confident kangdaseo001post
Post #1219124
Posted Friday, December 9, 2011 1:40 AM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: General Forum Members
Last Login: Friday, December 9, 2011 1:38 AM
Points: 2, Visits: 0
Ugg Boots Tall Classic Pink are Made of 100% premiun wool, so it's comfortable, the tall Timberland 6 Inch Boots Men href="http://www.boots2canada.com/ugg-boots-jimmy-choo-c-19/">Jimmy Choo Ugg Boots boots make Ugg Jimmy [b]Timberland Chukka Boots Sale Choo Timberland Boots Sale[/b] you look more elegant Ugg Boots Kids ugg australia amberlee boots Ugg Classic Boots Tall Chocolate are so cool and warm for you.Classic Ugg Kids style can match with Kids Ugg Boots href="http://www.boots2canada.com/ugg-fox-fur-boots-c-21/">Fox Fur Ugg Boots your jeans well and the top ed here Kids Ugg Boots now Atlantic Ugg Jimmy Choo Kaia Ugg Boots Canada Leopard Boots makes you attractive Ugg Boots Canada and confident. Mens Timberland 6 Inch Boots Black With White Timberland Words has great outside looking with the generous log pattern. High quality with premium full-grain waterproof leather and seam-sealed kangdaseo001post
Post #1219125
Posted Friday, December 9, 2011 1:45 AM
SSC Eights!

SSC Eights!SSC Eights!SSC Eights!SSC Eights!SSC Eights!SSC Eights!SSC Eights!SSC Eights!

Group: General Forum Members
Last Login: Wednesday, December 10, 2014 6:37 AM
Points: 885, Visits: 554
One comment - 'Dynamic Ports being the default for named instances'. The port is only truly dynamic for the installation of SQL Server - once it's installed, the port number is static and does not change.

So SPNs and Kerberos will work fine with named instances and dynamic ports. You just need to identify the correct port number after installation is complete.



Post #1219126
Posted Friday, December 9, 2011 2:55 AM


Old Hand

Old HandOld HandOld HandOld HandOld HandOld HandOld HandOld Hand

Group: General Forum Members
Last Login: Saturday, August 23, 2014 6:03 AM
Points: 351, Visits: 1,556
Kenneth, an excellent effort at covering a challenging a topic. Good stuff!

One question I imagine other readers might have, "how would the implementation steps differ, if at all, were both ServerA and ServerB using the same SQL Server Service Account?".



John Sansom (@sqlBrit) | www.johnsansom.com
Post #1219174
Posted Friday, December 9, 2011 3:45 AM
SSCertifiable

SSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiable

Group: General Forum Members
Last Login: Yesterday @ 11:57 AM
Points: 5,888, Visits: 13,062
Kenneth, thanks for the article. couple of points: are you sure the SQL restart is necessary to get this working, and the error you will often see returned with the double hop scenario is 'cannot generate SSPI context'

Heres another good source on kerberos, linked servers and double hop

http://blogs.msdn.com/b/sql_protocols/archive/2006/08/10/694657.aspx.

Has anyone got this working when the first hop is to SQL server and the second to AD itself (i.e. an ADSI linked server set up)


---------------------------------------------------------------------

Post #1219194
Posted Friday, December 9, 2011 3:55 AM


SSC-Addicted

SSC-AddictedSSC-AddictedSSC-AddictedSSC-AddictedSSC-AddictedSSC-AddictedSSC-AddictedSSC-Addicted

Group: General Forum Members
Last Login: Saturday, July 12, 2014 6:44 AM
Points: 441, Visits: 1,799
Kenneth

Very good article. A succinct way to get this to go.

For those that want a bit more depth, Brian Kelly wrote a good article at http://www.sqlservercentral.com/articles/Security/65169/

HTH

Dave J



http://glossopian.co.uk/
"I don't know what I don't know."
Post #1219202
Posted Friday, December 9, 2011 4:09 AM
Old Hand

Old HandOld HandOld HandOld HandOld HandOld HandOld HandOld Hand

Group: General Forum Members
Last Login: Friday, May 2, 2014 3:39 AM
Points: 350, Visits: 475
Thanks for this brief overview !
Franky


Franky L.
Post #1219213
Posted Friday, December 9, 2011 5:00 AM
SSC Rookie

SSC RookieSSC RookieSSC RookieSSC RookieSSC RookieSSC RookieSSC RookieSSC Rookie

Group: General Forum Members
Last Login: Thursday, July 11, 2013 1:19 PM
Points: 31, Visits: 100
stevehindmarsh (12/9/2011)
One comment - 'Dynamic Ports being the default for named instances'. The port is only truly dynamic for the installation of SQL Server - once it's installed, the port number is static and does not change.

So SPNs and Kerberos will work fine with named instances and dynamic ports. You just need to identify the correct port number after installation is complete.


Not true. What you are referring to is that SS will try to reuse the current dynamic port, it never becomes 'static'. If it's available it will use it again. If it has been grabbed by another application, it will renegotiate, FTP-style, a new port. It is especially true if one restarts the SS service, or takes the server off-line.
Post #1219255
Posted Friday, December 9, 2011 5:35 AM


Hall of Fame

Hall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of Fame

Group: General Forum Members
Last Login: Yesterday @ 1:17 PM
Points: 3,467, Visits: 1,840
John.Sansom (12/9/2011)
Kenneth, an excellent effort at covering a challenging a topic. Good stuff!

One question I imagine other readers might have, "how would the implementation steps differ, if at all, were both ServerA and ServerB using the same SQL Server Service Account?".


While I have to admit I have never tried itmy understanding is that each instance of SQL Server must have a different service account for this to work.


Kenneth Fisher
I strive to live in a world where a chicken can cross the road without being questioned about its motives.
--------------------------------------------------------------------------------
For better, quicker answers on T-SQL questions, click on the following...
http://www.sqlservercentral.com/articles/Best+Practices/61537/
For better answers on performance questions, click on the following...
http://www.sqlservercentral.com/articles/SQLServerCentral/66909/

Link to my Blog Post --> www.SQLStudies.com
Post #1219265
« Prev Topic | Next Topic »

Add to briefcase 12345»»»

Permissions Expand / Collapse