-

 -

- (0)

    ...

- (1)

.   - "...

- (0)

. " ". &...

- (0)

. - . - :http://www.tutdizain.ru...

- (0)

- " ". (, ...

 -

 -

        2
2
04:28 07.02.2011
: 314
07:54 06.02.2011
: 285
03:00 01.01.1970
: 0

 -

   Pinicillin

 - e-mail

 

 -

 LiveInternet.ru:
: 05.02.2011
: 241
: 33
: 328

:


Kerberos SharePoint

, 06 2011 . 04:00 +

  SharePoint , NTLM Kerberos. Windows /. NTLM IIS, , , , . NTLM , ( ) . Kerberos, , , (Key Distribution Center, KDC), , . Kerberos .


NTLM, , , . , , NTLM: , , , . , 832769 : "… - (SPN), NTLM. Kerberos SPN, SharePoint". , , SPN , Kerberos, - . , , Kerberos .
 

, Kerberos, Kerberos , . , NTLM , NTLM, , IIS SharePoint, , - - SharePoint -. , . , (Kerberos) , , . , .

NTLM Kerberos, , , (SSP) , . . , Kerberos . 871179, 962943 832769, , , , STOP. , , Microsoft Kerberos, IIS 7 , SPN. , Kerberos SharePoint, . , . Microsoft , 832769 953130 KB, .
 



SharePoint, Windows. , NTLM Kerberos, , - SharePoint.aspx, .NET IIS . , SQL Server . IIS SharePoint 2007 . 1. -, IIS, , , , , IIdentity, IPrincipal, . IIdentity IPrincipal HttpContext.User, , .NET, . 1.
 

. 1.         SharePoint

. 1. SharePoint

:

  1. SharePoint ( IIS .NET) HTTP GET.
  2. (, ), IIS . IIS 401.2 .
  3. , . AcquireCredentialsHandle /, SharePoint IIS.
  4. IIS HTTP , . IIS SharePoint .NET.
  5. -, SQL, SharePoint SQL Server . SQL . , SQL Server Windows NTLM Kerberos. Kerberos NTLM .
  6.  

SharePoint , : , IIS .NET SQL Server. .aspx, , IIS SQL Server. , , NTLM , SQL Server , IIS. IIS. .NET, : Windows ASP.NET 2.0.
 

NTLM Kerberos

, , Windows Server, IIS .NET , , Windows NTLM Kerberos. , NTLM Kerberos , NTLM /, . Kerberos , . , , . . 2 , SharePoint NTLM.
 

. 2.   NTLM  SharePoint

. 2. NTLM SharePoint

. 2, NTLM . , . , , , . . NTLM, , MaxConcurrentApi, NTLM /, .

NTLM :

  1. , , SharePoint IIS .NET HTTP GET .
  2. IIS 401.2 NTLM (WWW-Authenticate: NTLM).
  3. InitializeSecurityContext , , IIS.
  4. IIS NTLM.
  5. ( ), .
  6. IIS . , .
  7. , . , IIS, IIS .
  8. - SQL Server , .aspx.
  9.  

- Kerberos - , , Kerberos NTLM, , , Kerberos, . Kerberos SPN. WSS, MOSS, - - IIS, , . , , - . , IIS , . Kerberos SharePoint, SPN .

Kerberos Kerberos, , , SPN. . , Kerberos DNS Active Directory BIND SRV, TCP/IP . , Windows Server 2003 2008 DNS, , . . 3 Kerberos SharePoint.
 

. 3.      Kerberos

. 3. Kerberos

  1. NTLM, HTTP GET, (FQDN ).
  2. 401.2 — WWW-Authenticate: / WWW-Authenticate. Kerberos , Kerberos. , .
  3. SPN, , , .
  4. SPN, .
  5. IIS-, , , , ( ) .
  6. , IIS, -, SQL, SQL Server .
  7. SPN , , - , .
  8. SQL Server , -, . SQL Server , .NET .aspx .

SPN

SPN Kerberos, , . , , , Windows , , — SPN. , , SPN , -, .

SPN , . Active Directory Service-Principal-Name ( -). SPN. , SPN, . SPN Kerberos. SPN, SPN, SPN, .

SPN , Kerberos . SPN : , , , , . , service class/host: port. SharePoint HTTP MSSqlSvc. . — FQDN NetBIOS, . SPN, SPN NetBIOS, FQDN, , , .

, , SPN. , Active Directory, SPN HOST/<NetBIOSname> HOST/<FQDN>. , , SPN . - , , . , , , "" SQL Server, . .
 



Kerberos SQL Server, . SQL Server , , , , , .. Active Directory DNS. Kerberos, SharePoint , , , Excel SQL. SPN, SQL Server , .

Kerberos SQL Server . SPN, , Kerberos, NTLM. NetBIOS FQDN MSSQLSvc/<NetBIOS_Name>:1433 MSSQLSvc//<FQDN-hostname.domain.local>:1433, , — 1433. setspn ADSIEdit SPN, setspn , . ADSIEdit, , SPN servicePrincipalName. SPN setspn-A MSSQLSvc/<NetBIOS_Name>:1433 <domain>\<username> and setspn-A MSSQLSvc/<FQDNe>:1433 <domain>\<username>, SQL.

, SQL Server Kerberos, , , Wireshark, Kerbtray.exe . SQL SQL Server Management Studio, Event ID 540, , Kerberos. Kerberos SQL.
 



, Kerberos SQL Server, SharePoint, SPN , Kerberos (SSP) -, . SPN , SQL Server, SPN. SPN, , , SPN , . FQDN, NetBIOS . . 4 SPN, .
 

. 4.  SPN    MOSS

. 4. SPN MOSS

SPN. -, SPN - SharePoint , - IIS. , . , , SPN . -, HTTP HTTPS, . -, , , IIS SPN SSP. Kerberos (Office SharePoint Server).

, , Kerberos . , Kerberos . Kerberos , , , . " Active Directory" . Trust this user/computer ( /) (Kerberos) Delegation () . , SQL Server, (SSPAdmin, MySite, -) .

, Component Services ( ). Impersonation Level = Delegate. IIS WAMREG Admin Service, Security Local Activation . KB 917409 920783 .

— Kerberos SSP -. SharePoint SharePoint. , Authentication Providers Application Management, , Default Negotiate (Kerberos). iisreset /noforce , , Kerberos SSP.
 

IIS 7 Windows Server 2008

SharePoint 2007 Windows Server 2003 IIS 6. Windows Server 2008 IIS 7, . , , IIS 7 Kerberos . , ( ) , . IIS 7 . , . , . , , , , . , ( Kerberos IIS, IIS Kerberos , , LocalSystem).

Kerberos SharePoint, IIS 7, %WinDir%\System32\inetsrv\config\ApplicationHost.config ( ). .

<system.webServer>
<security>
<authentication>
<windowsAuthentication enabled="true" useKernelMode="true" useAppPoolCredentials="true" />
</authentication>
</security>
</system.webServer>

iisreset /noforce , , , , 962943 .

; (<identity impersonate="true" /> web.config) , validateIntegratedModeConfiguration "false" .aspx .
 



Kerberos , , Kerberos. Microsoft II7, , . Kerberos . , , Kerberos. , , , , Kerberos.
 

  1.  
::::::/Sharepoint
:  

: [1] []
 

:
: 

: ( )

:

  URL