Kerberos SharePoint |
SharePoint , NTLM Kerberos. Windows /. NTLM IIS, , , , . NTLM , ( ) . Kerberos, , , (Key Distribution Center, KDC), , . Kerberos .
NTLM, , , . , , NTLM: , , , . , 832769 : "… - (SPN), NTLM. Kerberos SPN, SharePoint". , , SPN , Kerberos, - . , , Kerberos .
, Kerberos, Kerberos , . , NTLM , NTLM, , IIS SharePoint, , - - SharePoint -. , . , (Kerberos) , , . , .
NTLM Kerberos, , , (SSP) , . . , Kerberos . 871179, 962943 832769, , , , STOP. , , Microsoft Kerberos, IIS 7 , SPN. , Kerberos SharePoint, . , . Microsoft , 832769 953130 KB, .
SharePoint, Windows. , NTLM Kerberos, , - SharePoint.aspx, .NET IIS . , SQL Server . IIS SharePoint 2007 . 1. -, IIS, , , , , IIdentity, IPrincipal, . IIdentity IPrincipal HttpContext.User, , .NET, . 1.
. 1. SharePoint
:
SharePoint , : , IIS .NET SQL Server. .aspx, , IIS SQL Server. , , NTLM , SQL Server , IIS. IIS. .NET, : Windows ASP.NET 2.0.
NTLM Kerberos
, , Windows Server, IIS .NET , , Windows NTLM Kerberos. , NTLM Kerberos , NTLM /, . Kerberos , . , , . . 2 , SharePoint NTLM.
. 2. NTLM SharePoint
. 2, NTLM . , . , , , . . NTLM, , MaxConcurrentApi, NTLM /, .
NTLM :
- Kerberos - , , Kerberos NTLM, , , Kerberos, . Kerberos SPN. WSS, MOSS, - - IIS, , . , , - . , IIS , . Kerberos SharePoint, SPN .
Kerberos Kerberos, , , SPN. . , Kerberos DNS Active Directory BIND SRV, TCP/IP . , Windows Server 2003 2008 DNS, , . . 3 Kerberos SharePoint.
. 3. Kerberos
SPN
SPN Kerberos, , . , , , Windows , , — SPN. , , SPN , -, .
SPN , . Active Directory Service-Principal-Name ( -). SPN. , SPN, . SPN Kerberos. SPN, SPN, SPN, .
SPN , Kerberos . SPN : , , , , . , service class/host: port. SharePoint HTTP MSSqlSvc. . — FQDN NetBIOS, . SPN, SPN NetBIOS, FQDN, , , .
, , SPN. , Active Directory, SPN HOST/<NetBIOSname> HOST/<FQDN>. , , SPN . - , , . , , , "" SQL Server, . .
Kerberos SQL Server, . SQL Server , , , , , .. Active Directory DNS. Kerberos, SharePoint , , , Excel SQL. SPN, SQL Server , .
Kerberos SQL Server . SPN, , Kerberos, NTLM. NetBIOS FQDN MSSQLSvc/<NetBIOS_Name>:1433 MSSQLSvc//<FQDN-hostname.domain.local>:1433, , — 1433. setspn ADSIEdit SPN, setspn , . ADSIEdit, , SPN servicePrincipalName. SPN setspn-A MSSQLSvc/<NetBIOS_Name>:1433 <domain>\<username> and setspn-A MSSQLSvc/<FQDNe>:1433 <domain>\<username>, SQL.
, SQL Server Kerberos, , , Wireshark, Kerbtray.exe . SQL SQL Server Management Studio, Event ID 540, , Kerberos. Kerberos SQL.
, Kerberos SQL Server, SharePoint, SPN , Kerberos (SSP) -, . SPN , SQL Server, SPN. SPN, , , SPN , . FQDN, NetBIOS . . 4 SPN, .
. 4. SPN MOSS
SPN. -, SPN - SharePoint , - IIS. , . , , SPN . -, HTTP HTTPS, . -, , , IIS SPN SSP. Kerberos (Office SharePoint Server).
, , Kerberos . , Kerberos . Kerberos , , , . " Active Directory" . Trust this user/computer ( /) (Kerberos) Delegation () . , SQL Server, (SSPAdmin, MySite, -) .
, Component Services ( ). Impersonation Level = Delegate. IIS WAMREG Admin Service, Security Local Activation . KB 917409 920783 .
— Kerberos SSP -. SharePoint SharePoint. , Authentication Providers Application Management, , Default Negotiate (Kerberos). iisreset /noforce , , Kerberos SSP.
IIS 7 Windows Server 2008
SharePoint 2007 Windows Server 2003 IIS 6. Windows Server 2008 IIS 7, . , , IIS 7 Kerberos . , ( ) , . IIS 7 . , . , . , , , , . , ( Kerberos IIS, IIS Kerberos , , LocalSystem).
Kerberos SharePoint, IIS 7, %WinDir%\System32\inetsrv\config\ApplicationHost.config ( ). .
<system.webServer>
<security>
<authentication>
<windowsAuthentication enabled="true" useKernelMode="true" useAppPoolCredentials="true" />
</authentication>
</security>
</system.webServer>
iisreset /noforce , , , , 962943 .
; (<identity impersonate="true" /> web.config) , validateIntegratedModeConfiguration "false" .aspx .
Kerberos , , Kerberos. Microsoft II7, , . Kerberos . , , Kerberos. , , , , Kerberos.
: | ::::::/Sharepoint |