on 12-09-2010 4:28 PM
Has anyone run ktpass out of the 64-bit directory (c:\windows\system32) successfully and if so, did you have UAC on or off?
The reason I ask is I am getting:
Targeting domain controller: blacklocust03.bobsautoparts.com
Using legacy password setting method
Failed to set property 'servicePrincipalName' to 'CRSSO/crystal_user.bobsautoparts.com' on Dn 'CN=Crystal Service,OU=Service Accounts,DC=bobsautoparts,DC=com': 0x32
.
WARNING: Unable to set SPN mapping data.
If crystal_user already has an SPN mapping installed for CRSSO/crystal_user.bobsautoparts.com, this is no cause for concern.
Aborted.
I googled and ran into this post: http://www.chaj.com/post/5312657/uac-and-ktpass-exe and I am trying to figure out my issue.
Perry Hoekstra
Edited by: Perry Hoekstra on Dec 9, 2010 9:32 PM
I'm pretty sure you can ignore that error run setspn - L serviceaccount and see if the SPN is set?
If not then it's really a Microsoft issue. I was able to run it on my 2008 SP2 64 bit, and I don't recall any issues. I did have UAT turned off.
Regards,
Tim
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
The underlying reason was Microsoft. Even though I had administration rights on the box, I did not have the necessary rights on the Domain Controller. As usual, the error message and code were less than illuminating which causes you to thrash around trying to figure out why all the parts don't mesh.
Perry Hoekstra
Considering that for Windows 2008 server, many of the management consoles used to manage Windows Server 2008 have been updated or completely redesigned, how do you "Verify the account UPN" and "Trust this user for delegation to any service (Kerberos only)"? I am referring to page 6/7 of your Configuring Vintella SSO in Distributed Environments document.
Hi Perry
If it is Windows 2008, then open the command prompt as Administrator and then execute your ktpass command.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
User | Count |
---|---|
88 | |
10 | |
10 | |
9 | |
7 | |
7 | |
6 | |
5 | |
4 | |
4 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.