Presentation is loading. Please wait.

Presentation is loading. Please wait.

AuthenticationService Application DelegationKerberos.

Similar presentations


Presentation on theme: "AuthenticationService Application DelegationKerberos."— Presentation transcript:

1

2

3 AuthenticationService Application DelegationKerberos

4

5

6

7 Web Application Application Servers (machine instance) Service Application Proxy Machine Instance WFE Service Instance C2WTS

8

9 Claims Bob Kerberos WFE Service App SQL Windows Claims C2WTS

10 UPN

11 Claims SAML WFEAPPSQL Bob SSRS SAML C2WTS SAML Kerb Kerberos S4U Logon AD Windows Claims

12

13 Requires Constrained DelegationAct as operating system

14 http://technet.microsoft.com/en-us/library/hh831747.aspx RBCDLarge TicketsClaimsFAST ArmoringSetSPN KDC ProxyKDC Events Operations Logs Performance Counters And More…

15

16

17

18

19

20 PowerShell Commands: Set-ADUser Set-ADComputer Set-AD-ServiceAccount Must be configured via PowerShell PrincipalsAllowedToDelegateToAccount parameter You specify this on the service you want to delegate to!

21

22

23

24 Domain Account Managed Service Account Virtual Service Account Local/Built-in Account

25 Normal AD User Accounts No Change in Kerberos Setup Guidance Register the SPN to the service account – Setspn -S MSSqlSvc/SQL:1433 vmlab\svcSql – Setspn -S MSSqlSvc/SQL vmlab\svcSql

26 Active Directory Managed – handles passwords and SPNs Requires 2008 R2 schema or greater Must create via PowerShell – Create the MSA in AD. – Associate the MSA with a computer in AD. – Install the MSA on the computer that was associated. – Configure the service(s) to use the MSA. Account Name 15 Characters or less

27

28

29 BISM

30

31

32

33 MySPC

34 Q&A

35


Download ppt "AuthenticationService Application DelegationKerberos."

Similar presentations


Ads by Google