Kerberos SPN for one FQDN on multiple serversIE Kerberos failure on some machines with CNAME web server (with SPN for host's A record)need help in setting up SPN for Kerberos AuthenticationMultiple SPNEGO authenticated web servers on one host nameSPN's, Kerberos and IISWhy is Kerberos security failing for our ADFS proxy server?How exactly does the HOST/machine SPN work?Adding new SPNs to existing service idsIs the Kerberos SPN FQDN significant to the server, or is the keytab enough?IE HTTP Kerberos issues authenticating to site on FQDN not matching AD DomainKerberos Apache keeps asking for BASIC
How is it possible to have an ability score that is less than 3?
Mage Armor with Defense fighting style (for Adventurers League bladeslinger)
tikz: show 0 at the axis origin
I’m planning on buying a laser printer but concerned about the life cycle of toner in the machine
Test if tikzmark exists on same page
How do I create uniquely male characters?
What would happen to a modern skyscraper if it rains micro blackholes?
Modeling an IPv4 Address
Prove that NP is closed under karp reduction?
Is it possible to do 50 km distance without any previous training?
How could an uplifted falcon's brain work?
Test whether all array elements are factors of a number
"to be prejudice towards/against someone" vs "to be prejudiced against/towards someone"
What typically incentivizes a professor to change jobs to a lower ranking university?
Can I make popcorn with any corn?
Is it important to consider tone, melody, and musical form while writing a song?
Theorems that impeded progress
To string or not to string
LaTeX closing $ signs makes cursor jump
What are the differences between the usage of 'it' and 'they'?
What's the point of deactivating Num Lock on login screens?
Is it legal for company to use my work email to pretend I still work there?
Is it unprofessional to ask if a job posting on GlassDoor is real?
How can bays and straits be determined in a procedurally generated map?
Kerberos SPN for one FQDN on multiple servers
IE Kerberos failure on some machines with CNAME web server (with SPN for host's A record)need help in setting up SPN for Kerberos AuthenticationMultiple SPNEGO authenticated web servers on one host nameSPN's, Kerberos and IISWhy is Kerberos security failing for our ADFS proxy server?How exactly does the HOST/machine SPN work?Adding new SPNs to existing service idsIs the Kerberos SPN FQDN significant to the server, or is the keytab enough?IE HTTP Kerberos issues authenticating to site on FQDN not matching AD DomainKerberos Apache keeps asking for BASIC
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
This is a bit of a weird one. I'm building a new web server hosted on a LAMP stack to replace an old IIS server. Its intended DNS name is currently occupied by the old server. I have SSL certificates set up for the new server, and configs ready to move the DNS over, but I'd like to have an SPN/TGT (HTTP/fqdn@domain) set up on the host in advance as well. I can have a separate service account to maintain it, problem is the FQDN is currently occupied.
Will creating that SPN on the LAMP host rob the IIS host of the ability to authenticate users through kerberos?
kerberos spn
New contributor
add a comment |
This is a bit of a weird one. I'm building a new web server hosted on a LAMP stack to replace an old IIS server. Its intended DNS name is currently occupied by the old server. I have SSL certificates set up for the new server, and configs ready to move the DNS over, but I'd like to have an SPN/TGT (HTTP/fqdn@domain) set up on the host in advance as well. I can have a separate service account to maintain it, problem is the FQDN is currently occupied.
Will creating that SPN on the LAMP host rob the IIS host of the ability to authenticate users through kerberos?
kerberos spn
New contributor
Why do you want the server to have the same name? There's almost never a good reason for this, and it's not technically necessary.
– Michael Hampton♦
Apr 3 at 16:06
add a comment |
This is a bit of a weird one. I'm building a new web server hosted on a LAMP stack to replace an old IIS server. Its intended DNS name is currently occupied by the old server. I have SSL certificates set up for the new server, and configs ready to move the DNS over, but I'd like to have an SPN/TGT (HTTP/fqdn@domain) set up on the host in advance as well. I can have a separate service account to maintain it, problem is the FQDN is currently occupied.
Will creating that SPN on the LAMP host rob the IIS host of the ability to authenticate users through kerberos?
kerberos spn
New contributor
This is a bit of a weird one. I'm building a new web server hosted on a LAMP stack to replace an old IIS server. Its intended DNS name is currently occupied by the old server. I have SSL certificates set up for the new server, and configs ready to move the DNS over, but I'd like to have an SPN/TGT (HTTP/fqdn@domain) set up on the host in advance as well. I can have a separate service account to maintain it, problem is the FQDN is currently occupied.
Will creating that SPN on the LAMP host rob the IIS host of the ability to authenticate users through kerberos?
kerberos spn
kerberos spn
New contributor
New contributor
New contributor
asked Apr 3 at 16:03
Philippe HaussmannPhilippe Haussmann
1
1
New contributor
New contributor
Why do you want the server to have the same name? There's almost never a good reason for this, and it's not technically necessary.
– Michael Hampton♦
Apr 3 at 16:06
add a comment |
Why do you want the server to have the same name? There's almost never a good reason for this, and it's not technically necessary.
– Michael Hampton♦
Apr 3 at 16:06
Why do you want the server to have the same name? There's almost never a good reason for this, and it's not technically necessary.
– Michael Hampton♦
Apr 3 at 16:06
Why do you want the server to have the same name? There's almost never a good reason for this, and it's not technically necessary.
– Michael Hampton♦
Apr 3 at 16:06
add a comment |
1 Answer
1
active
oldest
votes
In fact it will not be possible to associate the same SPN to the new principal until it's removed from the old principal. On the off chance you can convince AD to have it duplicated on multiple principals you're going to have weird results trying to get a kerberos ticket. Depending on a number of factors it'll either pick the original credential, new credential, or just barf because it found both.
So, don't do that. My recommendation is to treat the new service as unique up until you decommission the old server.
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Philippe Haussmann is a new contributor. Be nice, and check out our Code of Conduct.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f961333%2fkerberos-spn-for-one-fqdn-on-multiple-servers%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
In fact it will not be possible to associate the same SPN to the new principal until it's removed from the old principal. On the off chance you can convince AD to have it duplicated on multiple principals you're going to have weird results trying to get a kerberos ticket. Depending on a number of factors it'll either pick the original credential, new credential, or just barf because it found both.
So, don't do that. My recommendation is to treat the new service as unique up until you decommission the old server.
add a comment |
In fact it will not be possible to associate the same SPN to the new principal until it's removed from the old principal. On the off chance you can convince AD to have it duplicated on multiple principals you're going to have weird results trying to get a kerberos ticket. Depending on a number of factors it'll either pick the original credential, new credential, or just barf because it found both.
So, don't do that. My recommendation is to treat the new service as unique up until you decommission the old server.
add a comment |
In fact it will not be possible to associate the same SPN to the new principal until it's removed from the old principal. On the off chance you can convince AD to have it duplicated on multiple principals you're going to have weird results trying to get a kerberos ticket. Depending on a number of factors it'll either pick the original credential, new credential, or just barf because it found both.
So, don't do that. My recommendation is to treat the new service as unique up until you decommission the old server.
In fact it will not be possible to associate the same SPN to the new principal until it's removed from the old principal. On the off chance you can convince AD to have it duplicated on multiple principals you're going to have weird results trying to get a kerberos ticket. Depending on a number of factors it'll either pick the original credential, new credential, or just barf because it found both.
So, don't do that. My recommendation is to treat the new service as unique up until you decommission the old server.
answered 2 days ago
SteveSteve
24315
24315
add a comment |
add a comment |
Philippe Haussmann is a new contributor. Be nice, and check out our Code of Conduct.
Philippe Haussmann is a new contributor. Be nice, and check out our Code of Conduct.
Philippe Haussmann is a new contributor. Be nice, and check out our Code of Conduct.
Philippe Haussmann is a new contributor. Be nice, and check out our Code of Conduct.
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f961333%2fkerberos-spn-for-one-fqdn-on-multiple-servers%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Why do you want the server to have the same name? There's almost never a good reason for this, and it's not technically necessary.
– Michael Hampton♦
Apr 3 at 16:06