Click here to monitor SSC
SQLServerCentral is supported by Red Gate Software Ltd.
 
Log in  ::  Register  ::  Not logged in
 
 
 
        
Home       Members    Calendar    Who's On


Add to briefcase ««12

SQLCMD -S servername\instancename Error Expand / Collapse
Author
Message
Posted Tuesday, August 19, 2008 9:47 AM


SSCertifiable

SSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiableSSCertifiable

Group: General Forum Members
Last Login: Today @ 2:53 PM
Points: 6,630, Visits: 14,205
you can generate the SPN's manually using

SETSPN.EXE

syntax is
setspn -A ServiceClass/Host: Port AccountName

so for sql instance is

setspn -A MSSQLSvc/mysqlserver.domain.co.uk:staticsqlportnumber domain\sqlserviceuseraccount

use setspn -L domain\sqlserviceuseraccount

to list the SPN's



-----------------------------------------------------------------------------------------------------------

"Ya can't make an omelette without breaking just a few eggs"
Post #555133
Posted Saturday, August 23, 2008 1:29 AM


Hall of Fame

Hall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of Fame

Group: General Forum Members
Last Login: Wednesday, November 5, 2014 3:47 PM
Points: 3,087, Visits: 1,437
Hi Brian,

After testing giving the "Write Service PrincipalName" permission to a normal domain user (the account that starts the MSSQL service), I found out that it generates the SPN dynamically. I am planning to implement this on the production enviroment soon. Once again thank you for your help.





My blog
Post #557729
Posted Saturday, August 23, 2008 1:34 AM


Hall of Fame

Hall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of FameHall of Fame

Group: General Forum Members
Last Login: Wednesday, November 5, 2014 3:47 PM
Points: 3,087, Visits: 1,437
Perry, thanks for your reply. You are right, I can use the setspn command to create the SPN manually. It is a good way to do it, but to give the "write service principal name" permission to the domain account is more flexible and that's why I decide to choose that approach.




My blog
Post #557730
Posted Tuesday, February 22, 2011 6:17 AM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: General Forum Members
Last Login: Tuesday, September 24, 2013 8:48 AM
Points: 1, Visits: 24
Hi, just to clarify the Write/Read SPN permission on Active Directory is not recommended on clusters as for the active directory replication delay can make you have some problems as the registration need to be done before the service is brought up, and when the cluster node fail over the SPN is gonna get deleted and re-added, so for clusters this is not recommended.
Post #1067566
Posted Tuesday, April 19, 2011 3:10 AM


Ten Centuries

Ten CenturiesTen CenturiesTen CenturiesTen CenturiesTen CenturiesTen CenturiesTen CenturiesTen Centuries

Group: General Forum Members
Last Login: Today @ 11:16 AM
Points: 1,202, Visits: 1,944
I am currently getting the error in sql server logs:

2011-04-19 08:59:10 - ! [298] SQLServer Error: 802, Cannot generate SSPI context [SQLSTATE HY000]
2011-04-19 08:59:10 - ! [382] Logon to server '(local)' failed (JobManager)
2011-04-19 08:59:10 - ! [298] SQLServer Error: 802, SQL Network Interfaces: The target principal name is incorrect. [SQLSTATE HY000]
2011-04-19 08:59:10 - ! [298] SQLServer Error: 802, Cannot generate SSPI context [SQLSTATE HY000]
2011-04-19 08:59:10 - ! [382] Logon to server '(local)' failed (ConnUpdateJobActivity_NextScheduledRunDate)
2011-04-19 08:59:10 - ! [298] SQLServer Error: 802, SQL Network Interfaces: The target principal name is incorrect. [SQLSTATE HY000]
2011-04-19 08:59:10 - ! [298] SQLServer Error: 802, Cannot generate SSPI context [SQLSTATE HY000]
2011-04-19 08:59:10 - ! [382] Logon to server '(local)' failed (ConnAttemptCachableOp)
2011-04-19 08:59:10 - ! [298] SQLServer Error: 802, SQL Network Interfaces: The target principal name is incorrect. [SQLSTATE HY000]
2011-04-19 08:59:10 - ! [298] SQLServer Error: 802, Cannot generate SSPI context [SQLSTATE HY000]
2011-04-19 08:59:10 - ! [382] Logon to server '(local)' failed (ConnAttemptCachableOp)
2011-04-19 09:18:14 - ! [298] SQLServer Error: 802, SQL Network Interfaces: The target principal name is incorrect. [SQLSTATE HY000]
2011-04-19 09:18:14 - ! [298] SQLServer Error: 802, Cannot generate SSPI context [SQLSTATE HY000]
2011-04-19 09:18:14 - ! [382] Logon to server '(local)' failed (SaveAllSchedules)



Thanks

Post #1095474
« Prev Topic | Next Topic »

Add to briefcase ««12

Permissions Expand / Collapse