dbTalk Databases Forums  

Enable kerberos auth for cluster

microsoft.public.sqlserver.clustering microsoft.public.sqlserver.clustering


Discuss Enable kerberos auth for cluster in the microsoft.public.sqlserver.clustering forum.



Reply
 
Thread Tools Display Modes
  #1  
Old   
jacksors
 
Posts: n/a

Default Enable kerberos auth for cluster - 10-29-2008 , 05:51 AM






We are trying to enable kerberos authentication on our 2 node active/passive
SQL 2005 Ent cluster.

we have run the setspn -a MSSQLsvc/hostnameort domain\account command for
each host in the cluster and have verified using adsiedit that the SPN's
exist.

The AD computer accounts have the delegation tab and the "trust this
computer for delegation to any service(kerberos only)" is enabled.

When we go into the SQL cluster and go to the "SQL Network Name" resource
and check the "Enable Kerbos" on the parameters tab and try and bring that
resource online, it fails. The event viewer logs error 1194 saying "the
computer account for cluster resource 'sql network name blfsql01' in domain
domain.com could not be created for the following reason: unable to create
computer account"

The computer name referenced is the DNS name for the cluster, not an
individual host, so it should not need a computer account.

The Windows service account I used to create the SPN was the account used to
run the SQL Server DB engine.

Not really sure why we can not bring this online and what these errors are.
I've searched the web and red many MS articles, but none seem to give all the
steps required to get this working.

Any help would be greatly appreciated. Thanks.

Reply With Quote
Reply




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Powered by vBulletin Version 3.5.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.