Log in
::
Register
::
Not logged in
Home
Tags
Articles
Editorials
Stairways
Forums
Scripts
Videos
Blogs
QotD
Books
Ask SSC
SQL Jobs
Training
Authors
About us
Contact us
Newsletters
Write for us
Recent Posts
Recent Posts
Popular Topics
Popular Topics
Home
Search
Members
Calendar
Who's On
Home
»
Programming
»
Connecting
»
IIS 7, SQL, and Kerberos
IIS 7, SQL, and Kerberos
Rate Topic
Display Mode
Topic Options
Author
Message
schleep
schleep
Posted Wednesday, October 17, 2012 12:47 PM
Old Hand
Group: General Forum Members
Last Login: Tuesday, May 14, 2013 5:38 AM
Points: 344,
Visits: 601
Hey gang,
We're trying very hard to connect an internal webapp to an SQL Server 2008 R2.
I really want to know which authenticated user is connecting to SQL Server.
The IIS and SQL servers are on the same physical box.
I believe we are in the classic "double-hop" scenario.
The best info I've found so far is at:
http://www.adshotgyan.com/2011/01/kerberos-double-hop-troubleshooting_4351.html
We've worked through everything in that post, except we're using a single AD account, rather than the 2 in that example. It does not appear to be implied that 2 accounts must be used.
Questions:
When the Application Pool Defaults are set to use the AD domain account we've set up to connect, the connection is made to SQL Server via TCP, but it always uses NTLM, not Kerberos. If I remove NTLM as a provider in IIS - Authentication, I get a 401 - invalid credentials.
Can anyone point me to where to look next?
Thanks!
Post #1374005
schleep
schleep
Posted Thursday, October 18, 2012 7:02 AM
Old Hand
Group: General Forum Members
Last Login: Tuesday, May 14, 2013 5:38 AM
Points: 344,
Visits: 601
Progress!
Authentication Type: Negotiate
Protocol: Kerberos
Authenticated identity: Domain\Me
Thread identity: Domain\Me
Windows identity: Domain\SQL-Service
Environment identity: SQL-Service
We're now using Kerberos at least as far as the IIS Server!
So now we just need to get to the SQL Server...
Post #1374318
« Prev Topic
|
Next Topic »
Permissions
You
cannot
post new topics.
You
cannot
post topic replies.
You
cannot
post new polls.
You
cannot
post replies to polls.
You
cannot
edit your own topics.
You
cannot
delete your own topics.
You
cannot
edit other topics.
You
cannot
delete other topics.
You
cannot
edit your own posts.
You
cannot
edit other posts.
You
cannot
delete your own posts.
You
cannot
delete other posts.
You
cannot
post events.
You
cannot
edit your own events.
You
cannot
edit other events.
You
cannot
delete your own events.
You
cannot
delete other events.
You
cannot
send private messages.
You
cannot
send emails.
You
may
read topics.
You
cannot
rate topics.
You
cannot
vote within polls.
You
cannot
upload attachments.
You
may
download attachments.
You
cannot
post HTML code.
You
cannot
edit HTML code.
You
cannot
post IFCode.
You
cannot
post JavaScript.
You
cannot
post EmotIcons.
You
cannot
post or upload images.
Copyright © 2002-2013 Simple Talk Publishing. All Rights Reserved.
Privacy Policy.
Terms of Use.
Report Abuse.