To keep it simple and easy to follow/understand, I've list down the steps taken to make Kerberos work:
- Set SPN for all service accounts.
- Delegate trusts to the service accounts and machine accounts.
- For the WFEs, open up Local Security Policy then add the SharePoint site's application pool service account to "Act as part of the operating system" and "impersonate a client after authentication".
- Ensure all servers are able to ping each other and that the IP addresses and Hostnames are mapped correctly.
- Open up Central Administration site -> Applications -> Authentication Providers, make sure the correct web application is selected then change the authentication type to "Negotiate".
- For the WFEs, open up IIS and navigate to the SharePoint web applications -> Authentication -> Windows Integrated, then click on the Advanced settings. Uncheck to disable "Kernal-mode".
- For the WFEs, perform IISRESET /noforce
.jpg)
No comments:
Post a Comment